Search

Find a vulnerability

Search criteria

    206 vulnerabilities found for virtual_gpu by nvidia

    CVE-2024-0121 (GCVE-0-2024-0121)

    Vulnerability from nvd – Published: 2024-10-26 08:07 – Updated: 2024-11-01 03:55
    VLAI
    Summary
    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-31 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    NVIDIA GPU, vGPU, and Cloud Gaming Affected: All versions prior to 17.4, 16.8, and the October 2024 release
    Create a notification for this product.
    nvidia gpu_display_driver Affected: 565 , < 566.03 (custom)
    Affected: 550 , < 553.24 (custom)
    Affected: 535 , < 538.95 (custom)
        cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*
    Create a notification for this product.
    nvidia virtual_gpu Affected: 0 , < 16.8 (custom)
    Affected: 17.0 , < 17.4 (custom)
        cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia cloud_gaming_guest Affected: 0 , < 566.03 (custom)
        cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-10-26T09:02:46.116Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1955"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "gpu_display_driver",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "565",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "553.24",
                    "status": "affected",
                    "version": "550",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "538.95",
                    "status": "affected",
                    "version": "535",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "virtual_gpu",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "16.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "17.4",
                    "status": "affected",
                    "version": "17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "cloud_gaming_guest",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0121",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-31T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-01T03:55:24.794Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU, vGPU, and Cloud Gaming",
              "vendor": "NVIDIA",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions prior to 17.4, 16.8, and the October 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.\u003c/span\u003e\n\n\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e"
                }
              ],
              "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Code execution, denial of service, escalation of privileges, information disclosure, and data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-26T08:07:50.366Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5586"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0121",
        "datePublished": "2024-10-26T08:07:50.366Z",
        "dateReserved": "2023-12-02T00:42:31.930Z",
        "dateUpdated": "2024-11-01T03:55:24.794Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0120 (GCVE-0-2024-0120)

    Vulnerability from nvd – Published: 2024-10-26 08:06 – Updated: 2024-11-01 03:55
    VLAI
    Summary
    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-31 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    NVIDIA GPU, vGPU, and Cloud Gaming Affected: All versions prior to 17.4, 16.8, and the October 2024 release
    Create a notification for this product.
    nvidia gpu_display_driver Affected: 565 , < 566.03 (custom)
    Affected: 550 , < 553.24 (custom)
    Affected: 535 , < 538.95 (custom)
        cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*
    Create a notification for this product.
    nvidia virtual_gpu Affected: 0 , < 16.8 (custom)
    Affected: 17.0 , < 17.4 (custom)
        cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia cloud_gaming_guest Affected: 0 , < 566.03 (custom)
        cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-10-26T09:02:44.636Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2014"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "gpu_display_driver",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "565",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "553.24",
                    "status": "affected",
                    "version": "550",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "538.95",
                    "status": "affected",
                    "version": "535",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "virtual_gpu",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "16.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "17.4",
                    "status": "affected",
                    "version": "17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "cloud_gaming_guest",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0120",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-31T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-01T03:55:28.765Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU, vGPU, and Cloud Gaming",
              "vendor": "NVIDIA",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions prior to 17.4, 16.8, and the October 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.\u003c/span\u003e\n\n\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e"
                }
              ],
              "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Code execution, denial of service, escalation of privileges, information disclosure, and data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-26T08:06:52.882Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5586"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0120",
        "datePublished": "2024-10-26T08:06:52.882Z",
        "dateReserved": "2023-12-02T00:42:31.115Z",
        "dateUpdated": "2024-11-01T03:55:28.765Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0119 (GCVE-0-2024-0119)

    Vulnerability from nvd – Published: 2024-10-26 08:06 – Updated: 2024-11-01 03:55
    VLAI
    Summary
    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-31 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    NVIDIA GPU, vGPU, and Cloud Gaming Affected: All versions prior to 17.4, 16.8, and the October 2024 release
    Create a notification for this product.
    nvidia gpu_display_driver Affected: 565 , < 566.03 (custom)
    Affected: 550 , < 553.24 (custom)
    Affected: 535 , < 538.95 (custom)
        cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*
    Create a notification for this product.
    nvidia virtual_gpu Affected: 0 , < 16.8 (custom)
    Affected: 17.0 , < 17.4 (custom)
        cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia cloud_gaming_guest Affected: 0 , < 566.03 (custom)
        cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-10-26T09:02:43.217Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2015"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "gpu_display_driver",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "565",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "553.24",
                    "status": "affected",
                    "version": "550",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "538.95",
                    "status": "affected",
                    "version": "535",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "virtual_gpu",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "16.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "17.4",
                    "status": "affected",
                    "version": "17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "cloud_gaming_guest",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0119",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-31T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-01T03:55:25.799Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU, vGPU, and Cloud Gaming",
              "vendor": "NVIDIA",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions prior to 17.4, 16.8, and the October 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.\u003c/span\u003e\n\n\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e"
                }
              ],
              "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Code execution, denial of service, escalation of privileges, information disclosure, and data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-26T08:06:34.252Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5586"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0119",
        "datePublished": "2024-10-26T08:06:34.252Z",
        "dateReserved": "2023-12-02T00:42:30.310Z",
        "dateUpdated": "2024-11-01T03:55:25.799Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0118 (GCVE-0-2024-0118)

    Vulnerability from nvd – Published: 2024-10-26 08:06 – Updated: 2024-11-01 03:55
    VLAI
    Summary
    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-31 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    NVIDIA GPU, vGPU, and Cloud Gaming Affected: All versions prior to 17.4, 16.8, and the October 2024 release
    Create a notification for this product.
    nvidia gpu_display_driver Affected: 565 , < 566.03 (custom)
    Affected: 550 , < 553.24 (custom)
    Affected: 535 , < 538.95 (custom)
        cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*
    Create a notification for this product.
    nvidia virtual_gpu Affected: 0 , < 16.8 (custom)
    Affected: 17.0 , < 17.4 (custom)
        cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia cloud_gaming_guest Affected: 0 , < 566.03 (custom)
        cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-10-26T09:02:41.653Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2013"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "gpu_display_driver",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "565",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "553.24",
                    "status": "affected",
                    "version": "550",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "538.95",
                    "status": "affected",
                    "version": "535",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "virtual_gpu",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "16.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "17.4",
                    "status": "affected",
                    "version": "17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "cloud_gaming_guest",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0118",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-31T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-01T03:55:26.857Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU, vGPU, and Cloud Gaming",
              "vendor": "NVIDIA",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions prior to 17.4, 16.8, and the October 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.\u003c/span\u003e\n\n\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e"
                }
              ],
              "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Code execution, denial of service, escalation of privileges, information disclosure, and data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-26T08:06:27.506Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5586"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0118",
        "datePublished": "2024-10-26T08:06:27.506Z",
        "dateReserved": "2023-12-02T00:42:29.336Z",
        "dateUpdated": "2024-11-01T03:55:26.857Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0117 (GCVE-0-2024-0117)

    Vulnerability from nvd – Published: 2024-10-26 08:06 – Updated: 2024-11-01 03:55
    VLAI
    Summary
    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-31 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    NVIDIA GPU, vGPU, and Cloud Gaming Affected: All versions prior to 17.4, 16.8, and the October 2024 release
    Create a notification for this product.
    nvidia gpu_display_driver Affected: 565 , < 566.03 (custom)
    Affected: 550 , < 553.24 (custom)
    Affected: 535 , < 538.95 (custom)
        cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*
    Create a notification for this product.
    nvidia virtual_gpu Affected: 0 , < 16.8 (custom)
    Affected: 17.0 , < 17.4 (custom)
        cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia cloud_gaming_guest Affected: 0 , < 566.03 (custom)
        cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-10-26T09:02:40.089Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2012"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "gpu_display_driver",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "565",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "553.24",
                    "status": "affected",
                    "version": "550",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "538.95",
                    "status": "affected",
                    "version": "535",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "virtual_gpu",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "16.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "17.4",
                    "status": "affected",
                    "version": "17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "cloud_gaming_guest",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0117",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-31T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-01T03:55:27.833Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU, vGPU, and Cloud Gaming",
              "vendor": "NVIDIA",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions prior to 17.4, 16.8, and the October 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.\u003c/span\u003e\n\n\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e"
                }
              ],
              "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Code execution, denial of service, escalation of privileges, information disclosure, and data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-26T08:06:19.001Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5586"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0117",
        "datePublished": "2024-10-26T08:06:19.001Z",
        "dateReserved": "2023-12-02T00:42:28.257Z",
        "dateUpdated": "2024-11-01T03:55:27.833Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0107 (GCVE-0-2024-0107)

    Vulnerability from nvd – Published: 2024-08-08 16:57 – Updated: 2025-11-04 17:14
    VLAI
    Summary
    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-08 18:35 UTC
    CWE
    Impacted products
    Vendor Product Version
    NVIDIA GPU Display Driver, vGPU Software, Cloud Gaming Affected: All versions up to and including the June 2024 release
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0107",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-08T18:35:37.897108Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-08T18:36:36.982Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-04T17:14:08.942Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1956"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows"
              ],
              "product": "GPU Display Driver, vGPU Software, Cloud Gaming",
              "vendor": "NVIDIA",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including the June 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.\u003c/span\u003e"
                }
              ],
              "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Code execution, denial of service, escalation of privileges, information disclosure, data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-08T16:57:49.154Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5557"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0107",
        "datePublished": "2024-08-08T16:57:49.154Z",
        "dateReserved": "2023-12-02T00:42:17.123Z",
        "dateUpdated": "2025-11-04T17:14:08.942Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-0093 (GCVE-0-2024-0093)

    Vulnerability from nvd – Published: 2024-06-13 21:23 – Updated: 2024-08-19 17:01
    VLAI
    Title
    CVE
    Summary
    NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerability might lead to information disclosure.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-19 17:01 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia vGPU software and Cloud Gaming Affected: All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:16.016Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0093",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-19T17:01:41.169385Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-19T17:01:50.663Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "vGPU software and Cloud Gaming",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerability might lead to information disclosure."
                }
              ],
              "value": "NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerability might lead to information disclosure."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Information disclosure"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "CWE-200",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T21:23:29.967Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0093",
        "datePublished": "2024-06-13T21:23:29.967Z",
        "dateReserved": "2023-12-02T00:42:02.964Z",
        "dateUpdated": "2024-08-19T17:01:50.663Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0092 (GCVE-0-2024-0092)

    Vulnerability from nvd – Published: 2024-06-13 21:23 – Updated: 2024-08-01 17:41
    VLAI
    Title
    CVE
    Summary
    NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of exception conditions might lead to denial of service.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-17 16:45 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia GPU display driver, vGPU software, and Cloud Gaming Affected: All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0092",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-17T16:45:14.826848Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-17T16:45:23.624Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:15.947Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU display driver, vGPU software, and Cloud Gaming",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of exception conditions might lead to denial of service."
                }
              ],
              "value": "NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of exception conditions might lead to denial of service."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Denial of service"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-703",
                  "description": "CWE-703",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T21:23:30.327Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0092",
        "datePublished": "2024-06-13T21:23:30.327Z",
        "dateReserved": "2023-12-02T00:42:01.816Z",
        "dateUpdated": "2024-08-01T17:41:15.947Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0091 (GCVE-0-2024-0091)

    Vulnerability from nvd – Published: 2024-06-13 21:23 – Updated: 2024-08-01 17:41
    VLAI
    Title
    CVE
    Summary
    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-14 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia GPU display driver, vGPU software, and Cloud Gaming Affected: All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release
    Create a notification for this product.
    nvidia geforce Affected: 0 , < 555.99 (custom)
        cpe:2.3:a:nvidia:geforce:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia studio Affected: 0 , < 555.99 (custom)
        cpe:2.3:a:nvidia:studio:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia quadro_firmware Affected: 0 , < 555.99 (custom)
    Affected: 0 , < 552.55 (custom)
        cpe:2.3:a:nvidia:quadro_firmware:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia nvs_firmware Affected: 0 , < 555.99 (custom)
    Affected: 0 , < 552.55 (custom)
        cpe:2.3:a:nvidia:nvs_firmware:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia rtx Affected: 0 , < 555.99 (custom)
    Affected: 0 , < 552.55 (custom)
        cpe:2.3:a:nvidia:rtx:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia tesla Affected: 0 , < 552.55 (custom)
        cpe:2.3:a:nvidia:tesla:552.55:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:geforce:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "geforce",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:studio:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "studio",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:quadro_firmware:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "quadro_firmware",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "552.55",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:nvs_firmware:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "nvs_firmware",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "552.55",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:rtx:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "rtx",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "552.55",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:tesla:552.55:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "tesla",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "552.55",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0091",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-15T03:55:35.767Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:15.985Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU display driver, vGPU software, and Cloud Gaming",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering."
                }
              ],
              "value": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Denial of service, information disclosure, data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-822",
                  "description": "CWE-822",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T21:23:29.556Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0091",
        "datePublished": "2024-06-13T21:23:29.556Z",
        "dateReserved": "2023-12-02T00:42:00.978Z",
        "dateUpdated": "2024-08-01T17:41:15.985Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0090 (GCVE-0-2024-0090)

    Vulnerability from nvd – Published: 2024-06-13 21:23 – Updated: 2024-08-01 17:41
    VLAI
    Title
    CVE
    Summary
    NVIDIA GPU driver for Windows and Linux contains a vulnerability where a user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-14 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia GPU display driver, vGPU software, and Cloud Gaming Affected: All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release
    Create a notification for this product.
    nvidia gpu_display_driver Affected: 0 , ≤ 17.1 (custom)
    Affected: 0 , ≤ 16.5 (custom)
    Affected: 0 , ≤ 13.10 (custom)
        cpe:2.3:a:nvidia:gpu_display_driver:-:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia virtual_gpu Affected: 0 , ≤ 16.5 (custom)
    Affected: 0 , ≤ 17.1 (custom)
    Affected: 0 , ≤ 13.10 (custom)
        cpe:2.3:a:nvidia:virtual_gpu:-:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia cloud_gaming Affected: 0 , ≤ 13.10 (custom)
    Affected: 0 , ≤ 17.1 (custom)
    Affected: 0 , ≤ 16.5 (custom)
        cpe:2.3:a:nvidia:cloud_gaming:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:gpu_display_driver:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "gpu_display_driver",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThanOrEqual": "17.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "16.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "13.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:virtual_gpu:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "virtual_gpu",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThanOrEqual": "16.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "17.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "13.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:cloud_gaming:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "cloud_gaming",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThanOrEqual": "13.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "17.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "16.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0090",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-15T03:55:33.792Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:15.818Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU display driver, vGPU software, and Cloud Gaming",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA GPU driver for Windows and Linux contains a vulnerability where a user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering."
                }
              ],
              "value": "NVIDIA GPU driver for Windows and Linux contains a vulnerability where a user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Code execution, denial of service, escalation of privileges, information disclosure, data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T21:23:28.800Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0090",
        "datePublished": "2024-06-13T21:23:28.800Z",
        "dateReserved": "2023-12-02T00:41:59.934Z",
        "dateUpdated": "2024-08-01T17:41:15.818Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0089 (GCVE-0-2024-0089)

    Vulnerability from nvd – Published: 2024-06-13 21:23 – Updated: 2024-08-01 17:41
    VLAI
    Title
    CVE
    Summary
    NVIDIA GPU Display Driver for Windows contains a vulnerability where the information from a previous client or another process could be disclosed. A successful exploit of this vulnerability might lead to code execution, information disclosure, or data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-15 03:55 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia GPU display driver, vGPU software, and Cloud Gaming Affected: All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release
    Create a notification for this product.
    nvidia geforce Affected: 0 , < 555.99 (custom)
        cpe:2.3:a:nvidia:geforce:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia studio Affected: 0 , < 555.99 (custom)
        cpe:2.3:a:nvidia:studio:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia quadro_firmware Affected: 0 , < 555.99 (custom)
    Affected: 0 , < 552.55 (custom)
        cpe:2.3:a:nvidia:quadro_firmware:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia nvs_firmware Affected: 0 , < 555.99 (custom)
    Affected: 0 , < 552.55 (custom)
        cpe:2.3:a:nvidia:nvs_firmware:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia rtx Affected: 0 , < 555.99 (custom)
    Affected: 0 , < 552.55 (custom)
        cpe:2.3:a:nvidia:rtx:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia tesla Affected: 0 , < 552.55 (custom)
        cpe:2.3:a:nvidia:tesla:552.55:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:geforce:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "geforce",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:studio:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "studio",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:quadro_firmware:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "quadro_firmware",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "552.55",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:nvs_firmware:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "nvs_firmware",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "552.55",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:rtx:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "rtx",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "552.55",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:tesla:552.55:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "tesla",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "552.55",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0089",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-15T03:55:35.510137Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-17T12:53:30.805Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:15.971Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU display driver, vGPU software, and Cloud Gaming",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability where the information from a previous client or another process could be disclosed. A successful exploit of this vulnerability might lead to code execution, information disclosure, or data tampering."
                }
              ],
              "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability where the information from a previous client or another process could be disclosed. A successful exploit of this vulnerability might lead to code execution, information disclosure, or data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Code execution, information disclosure, data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-665",
                  "description": "CWE-665",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T21:23:29.198Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0089",
        "datePublished": "2024-06-13T21:23:29.198Z",
        "dateReserved": "2023-12-02T00:41:59.121Z",
        "dateUpdated": "2024-08-01T17:41:15.971Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0086 (GCVE-0-2024-0086)

    Vulnerability from nvd – Published: 2024-06-13 21:23 – Updated: 2024-08-01 17:41
    VLAI
    Title
    CVE
    Summary
    NVIDIA vGPU software for Linux contains a vulnerability where the software can dereference a NULL pointer. A successful exploit of this vulnerability might lead to denial of service and undefined behavior in the vGPU plugin.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-14 18:11 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia vGPU software and Cloud Gaming Affected: All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0086",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-14T18:11:14.627113Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-14T18:11:21.054Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:15.913Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "vGPU software and Cloud Gaming",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA vGPU software for Linux contains a vulnerability where the software can dereference a NULL pointer. A successful exploit of this vulnerability might lead to denial of service and undefined behavior in the vGPU plugin."
                }
              ],
              "value": "NVIDIA vGPU software for Linux contains a vulnerability where the software can dereference a NULL pointer. A successful exploit of this vulnerability might lead to denial of service and undefined behavior in the vGPU plugin."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Denial of service, undefined behavior"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-476",
                  "description": "CWE-476",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T21:23:32.289Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0086",
        "datePublished": "2024-06-13T21:23:32.289Z",
        "dateReserved": "2023-12-02T00:41:56.856Z",
        "dateUpdated": "2024-08-01T17:41:15.913Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0085 (GCVE-0-2024-0085)

    Vulnerability from nvd – Published: 2024-06-13 21:23 – Updated: 2024-08-19 17:00
    VLAI
    Title
    CVE
    Summary
    NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of service.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-19 16:56 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia vGPU software and Cloud Gaming Affected: All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release
    Create a notification for this product.
    nvidia virtual_gpu Affected: 0 , < 13.11 (custom)
    Affected: 14.0 , < 16.6 (custom)
    Affected: 17.0 , < 17.2 (custom)
        cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia cloud_gaming_virtual_gpu Affected: 0 , < 555.52.04 (custom)
        cpe:2.3:a:nvidia:cloud_gaming_virtual_gpu:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:15.760Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "virtual_gpu",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "13.11",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "16.6",
                    "status": "affected",
                    "version": "14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "17.2",
                    "status": "affected",
                    "version": "17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:cloud_gaming_virtual_gpu:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "cloud_gaming_virtual_gpu",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.52.04",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0085",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-19T16:56:23.736265Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-19T17:00:44.334Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "vGPU software and Cloud Gaming",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of service."
                }
              ],
              "value": "NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of service."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Data tampering, escalation of privileges, denial of service"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-266",
                  "description": "CWE-266",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T21:23:31.505Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0085",
        "datePublished": "2024-06-13T21:23:31.505Z",
        "dateReserved": "2023-12-02T00:41:56.027Z",
        "dateUpdated": "2024-08-19T17:00:44.334Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0084 (GCVE-0-2024-0084)

    Vulnerability from nvd – Published: 2024-06-13 21:23 – Updated: 2024-08-01 17:41
    VLAI
    Title
    CVE
    Summary
    NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could execute privileged operations. A successful exploit of this vulnerability might lead to information disclosure, data tampering, escalation of privileges, and denial of service.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-14 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia vGPU software and Cloud Gaming Affected: All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release
    Create a notification for this product.
    nvidia virtual_gpu_graphics_driver Affected: 0 , < 13.11 (custom)
    Affected: 0 , < 16.6 (custom)
    Affected: 0 , < 17.2 (custom)
        cpe:2.3:a:nvidia:virtual_gpu_graphics_driver:13.10:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:virtual_gpu_graphics_driver:13.10:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "virtual_gpu_graphics_driver",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "13.11",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "16.6",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "17.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0084",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-15T03:55:37.767Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:15.927Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "vGPU software and Cloud Gaming",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could execute privileged operations. A successful exploit of this vulnerability might lead to information disclosure, data tampering, escalation of privileges, and denial of service."
                }
              ],
              "value": "NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could execute privileged operations. A successful exploit of this vulnerability might lead to information disclosure, data tampering, escalation of privileges, and denial of service."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Information disclosure, data tampering, escalation of privileges, denial of service"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-250",
                  "description": "CWE-250",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T21:23:31.105Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0084",
        "datePublished": "2024-06-13T21:23:31.105Z",
        "dateReserved": "2023-12-02T00:41:55.036Z",
        "dateUpdated": "2024-08-01T17:41:15.927Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-31027 (GCVE-0-2023-31027)

    Vulnerability from nvd – Published: 2023-11-02 18:56 – Updated: 2024-09-12 13:30
    VLAI
    Title
    CVE
    Summary
    NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to escalate privileges when an administrator is updating GPU drivers, which may lead to escalation of privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-05 18:50 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Affected: All versions prior to and including 13.8, 15.3, 16.1 and all versions prior to and including September 2023 release
    Create a notification for this product.
    nvidia gpu_display_driver Affected: 0 , ≤ 16.1 (custom)
    Affected: 0 , ≤ September2023 (custom)
        cpe:2.3:a:nvidia:gpu_display_driver:-:*:*:*:*:windows:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T14:45:25.601Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5491"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:gpu_display_driver:-:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "gpu_display_driver",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThanOrEqual": "16.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "September2023",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-31027",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-05T18:50:25.619195Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-12T13:30:01.870Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions prior to and including 13.8, 15.3, 16.1 and all versions prior to and including September 2023 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to escalate privileges when an administrator is updating GPU drivers, which may lead to escalation of privileges."
                }
              ],
              "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to escalate privileges when an administrator is updating GPU drivers, which may lead to escalation of privileges."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Escalation of privileges"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-427",
                  "description": "CWE-427",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-11-02T18:56:23.410Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5491"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2023-31027",
        "datePublished": "2023-11-02T18:56:23.410Z",
        "dateReserved": "2023-04-22T02:38:27.192Z",
        "dateUpdated": "2024-09-12T13:30:01.870Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-31026 (GCVE-0-2023-31026)

    Vulnerability from nvd – Published: 2023-11-02 18:56 – Updated: 2024-09-05 14:34
    VLAI
    Title
    CVE
    Summary
    NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a NULL-pointer dereference may lead to denial of service.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-05 14:24 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia vGPU driver and Cloud gaming driver Affected: All versions prior to and including 13.8, 15.3, 16.1 and all versions prior to and including September 2023 release
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T14:45:25.000Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5491"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-31026",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-05T14:24:50.601821Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-05T14:34:42.757Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "vGPU driver and Cloud gaming driver",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions prior to and including 13.8, 15.3, 16.1 and all versions prior to and including September 2023 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a NULL-pointer dereference may lead to denial of service."
                }
              ],
              "value": "NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a NULL-pointer dereference may lead to denial of service."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Denial of service"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-476",
                  "description": "CWE-476",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-11-02T18:56:22.940Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5491"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2023-31026",
        "datePublished": "2023-11-02T18:56:22.940Z",
        "dateReserved": "2023-04-22T02:38:27.192Z",
        "dateUpdated": "2024-09-05T14:34:42.757Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0121 (GCVE-0-2024-0121)

    Vulnerability from cvelistv5 – Published: 2024-10-26 08:07 – Updated: 2024-11-01 03:55
    VLAI
    Summary
    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-31 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    NVIDIA GPU, vGPU, and Cloud Gaming Affected: All versions prior to 17.4, 16.8, and the October 2024 release
    Create a notification for this product.
    nvidia gpu_display_driver Affected: 565 , < 566.03 (custom)
    Affected: 550 , < 553.24 (custom)
    Affected: 535 , < 538.95 (custom)
        cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*
    Create a notification for this product.
    nvidia virtual_gpu Affected: 0 , < 16.8 (custom)
    Affected: 17.0 , < 17.4 (custom)
        cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia cloud_gaming_guest Affected: 0 , < 566.03 (custom)
        cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-10-26T09:02:46.116Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1955"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "gpu_display_driver",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "565",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "553.24",
                    "status": "affected",
                    "version": "550",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "538.95",
                    "status": "affected",
                    "version": "535",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "virtual_gpu",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "16.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "17.4",
                    "status": "affected",
                    "version": "17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "cloud_gaming_guest",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0121",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-31T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-01T03:55:24.794Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU, vGPU, and Cloud Gaming",
              "vendor": "NVIDIA",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions prior to 17.4, 16.8, and the October 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.\u003c/span\u003e\n\n\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e"
                }
              ],
              "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Code execution, denial of service, escalation of privileges, information disclosure, and data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-26T08:07:50.366Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5586"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0121",
        "datePublished": "2024-10-26T08:07:50.366Z",
        "dateReserved": "2023-12-02T00:42:31.930Z",
        "dateUpdated": "2024-11-01T03:55:24.794Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0120 (GCVE-0-2024-0120)

    Vulnerability from cvelistv5 – Published: 2024-10-26 08:06 – Updated: 2024-11-01 03:55
    VLAI
    Summary
    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-31 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    NVIDIA GPU, vGPU, and Cloud Gaming Affected: All versions prior to 17.4, 16.8, and the October 2024 release
    Create a notification for this product.
    nvidia gpu_display_driver Affected: 565 , < 566.03 (custom)
    Affected: 550 , < 553.24 (custom)
    Affected: 535 , < 538.95 (custom)
        cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*
    Create a notification for this product.
    nvidia virtual_gpu Affected: 0 , < 16.8 (custom)
    Affected: 17.0 , < 17.4 (custom)
        cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia cloud_gaming_guest Affected: 0 , < 566.03 (custom)
        cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-10-26T09:02:44.636Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2014"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "gpu_display_driver",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "565",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "553.24",
                    "status": "affected",
                    "version": "550",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "538.95",
                    "status": "affected",
                    "version": "535",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "virtual_gpu",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "16.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "17.4",
                    "status": "affected",
                    "version": "17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "cloud_gaming_guest",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0120",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-31T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-01T03:55:28.765Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU, vGPU, and Cloud Gaming",
              "vendor": "NVIDIA",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions prior to 17.4, 16.8, and the October 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.\u003c/span\u003e\n\n\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e"
                }
              ],
              "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Code execution, denial of service, escalation of privileges, information disclosure, and data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-26T08:06:52.882Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5586"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0120",
        "datePublished": "2024-10-26T08:06:52.882Z",
        "dateReserved": "2023-12-02T00:42:31.115Z",
        "dateUpdated": "2024-11-01T03:55:28.765Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0119 (GCVE-0-2024-0119)

    Vulnerability from cvelistv5 – Published: 2024-10-26 08:06 – Updated: 2024-11-01 03:55
    VLAI
    Summary
    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-31 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    NVIDIA GPU, vGPU, and Cloud Gaming Affected: All versions prior to 17.4, 16.8, and the October 2024 release
    Create a notification for this product.
    nvidia gpu_display_driver Affected: 565 , < 566.03 (custom)
    Affected: 550 , < 553.24 (custom)
    Affected: 535 , < 538.95 (custom)
        cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*
    Create a notification for this product.
    nvidia virtual_gpu Affected: 0 , < 16.8 (custom)
    Affected: 17.0 , < 17.4 (custom)
        cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia cloud_gaming_guest Affected: 0 , < 566.03 (custom)
        cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-10-26T09:02:43.217Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2015"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "gpu_display_driver",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "565",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "553.24",
                    "status": "affected",
                    "version": "550",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "538.95",
                    "status": "affected",
                    "version": "535",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "virtual_gpu",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "16.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "17.4",
                    "status": "affected",
                    "version": "17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "cloud_gaming_guest",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0119",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-31T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-01T03:55:25.799Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU, vGPU, and Cloud Gaming",
              "vendor": "NVIDIA",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions prior to 17.4, 16.8, and the October 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.\u003c/span\u003e\n\n\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e"
                }
              ],
              "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Code execution, denial of service, escalation of privileges, information disclosure, and data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-26T08:06:34.252Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5586"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0119",
        "datePublished": "2024-10-26T08:06:34.252Z",
        "dateReserved": "2023-12-02T00:42:30.310Z",
        "dateUpdated": "2024-11-01T03:55:25.799Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0118 (GCVE-0-2024-0118)

    Vulnerability from cvelistv5 – Published: 2024-10-26 08:06 – Updated: 2024-11-01 03:55
    VLAI
    Summary
    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-31 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    NVIDIA GPU, vGPU, and Cloud Gaming Affected: All versions prior to 17.4, 16.8, and the October 2024 release
    Create a notification for this product.
    nvidia gpu_display_driver Affected: 565 , < 566.03 (custom)
    Affected: 550 , < 553.24 (custom)
    Affected: 535 , < 538.95 (custom)
        cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*
    Create a notification for this product.
    nvidia virtual_gpu Affected: 0 , < 16.8 (custom)
    Affected: 17.0 , < 17.4 (custom)
        cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia cloud_gaming_guest Affected: 0 , < 566.03 (custom)
        cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-10-26T09:02:41.653Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2013"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "gpu_display_driver",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "565",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "553.24",
                    "status": "affected",
                    "version": "550",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "538.95",
                    "status": "affected",
                    "version": "535",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "virtual_gpu",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "16.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "17.4",
                    "status": "affected",
                    "version": "17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "cloud_gaming_guest",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0118",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-31T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-01T03:55:26.857Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU, vGPU, and Cloud Gaming",
              "vendor": "NVIDIA",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions prior to 17.4, 16.8, and the October 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.\u003c/span\u003e\n\n\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e"
                }
              ],
              "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Code execution, denial of service, escalation of privileges, information disclosure, and data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-26T08:06:27.506Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5586"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0118",
        "datePublished": "2024-10-26T08:06:27.506Z",
        "dateReserved": "2023-12-02T00:42:29.336Z",
        "dateUpdated": "2024-11-01T03:55:26.857Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0117 (GCVE-0-2024-0117)

    Vulnerability from cvelistv5 – Published: 2024-10-26 08:06 – Updated: 2024-11-01 03:55
    VLAI
    Summary
    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-31 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    NVIDIA GPU, vGPU, and Cloud Gaming Affected: All versions prior to 17.4, 16.8, and the October 2024 release
    Create a notification for this product.
    nvidia gpu_display_driver Affected: 565 , < 566.03 (custom)
    Affected: 550 , < 553.24 (custom)
    Affected: 535 , < 538.95 (custom)
        cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*
    Create a notification for this product.
    nvidia virtual_gpu Affected: 0 , < 16.8 (custom)
    Affected: 17.0 , < 17.4 (custom)
        cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia cloud_gaming_guest Affected: 0 , < 566.03 (custom)
        cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-10-26T09:02:40.089Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2012"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "gpu_display_driver",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "565",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "553.24",
                    "status": "affected",
                    "version": "550",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "538.95",
                    "status": "affected",
                    "version": "535",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "virtual_gpu",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "16.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "17.4",
                    "status": "affected",
                    "version": "17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:cloud_gaming_guest:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "cloud_gaming_guest",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "566.03",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0117",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-31T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-01T03:55:27.833Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU, vGPU, and Cloud Gaming",
              "vendor": "NVIDIA",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions prior to 17.4, 16.8, and the October 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.\u003c/span\u003e\n\n\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e"
                }
              ],
              "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Code execution, denial of service, escalation of privileges, information disclosure, and data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-26T08:06:19.001Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5586"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0117",
        "datePublished": "2024-10-26T08:06:19.001Z",
        "dateReserved": "2023-12-02T00:42:28.257Z",
        "dateUpdated": "2024-11-01T03:55:27.833Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0107 (GCVE-0-2024-0107)

    Vulnerability from cvelistv5 – Published: 2024-08-08 16:57 – Updated: 2025-11-04 17:14
    VLAI
    Summary
    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-08 18:35 UTC
    CWE
    Impacted products
    Vendor Product Version
    NVIDIA GPU Display Driver, vGPU Software, Cloud Gaming Affected: All versions up to and including the June 2024 release
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0107",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-08T18:35:37.897108Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-08T18:36:36.982Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-04T17:14:08.942Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1956"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows"
              ],
              "product": "GPU Display Driver, vGPU Software, Cloud Gaming",
              "vendor": "NVIDIA",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including the June 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.\u003c/span\u003e"
                }
              ],
              "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Code execution, denial of service, escalation of privileges, information disclosure, data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-08T16:57:49.154Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5557"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0107",
        "datePublished": "2024-08-08T16:57:49.154Z",
        "dateReserved": "2023-12-02T00:42:17.123Z",
        "dateUpdated": "2025-11-04T17:14:08.942Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-0086 (GCVE-0-2024-0086)

    Vulnerability from cvelistv5 – Published: 2024-06-13 21:23 – Updated: 2024-08-01 17:41
    VLAI
    Title
    CVE
    Summary
    NVIDIA vGPU software for Linux contains a vulnerability where the software can dereference a NULL pointer. A successful exploit of this vulnerability might lead to denial of service and undefined behavior in the vGPU plugin.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-14 18:11 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia vGPU software and Cloud Gaming Affected: All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0086",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-14T18:11:14.627113Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-14T18:11:21.054Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:15.913Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "vGPU software and Cloud Gaming",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA vGPU software for Linux contains a vulnerability where the software can dereference a NULL pointer. A successful exploit of this vulnerability might lead to denial of service and undefined behavior in the vGPU plugin."
                }
              ],
              "value": "NVIDIA vGPU software for Linux contains a vulnerability where the software can dereference a NULL pointer. A successful exploit of this vulnerability might lead to denial of service and undefined behavior in the vGPU plugin."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Denial of service, undefined behavior"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-476",
                  "description": "CWE-476",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T21:23:32.289Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0086",
        "datePublished": "2024-06-13T21:23:32.289Z",
        "dateReserved": "2023-12-02T00:41:56.856Z",
        "dateUpdated": "2024-08-01T17:41:15.913Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0085 (GCVE-0-2024-0085)

    Vulnerability from cvelistv5 – Published: 2024-06-13 21:23 – Updated: 2024-08-19 17:00
    VLAI
    Title
    CVE
    Summary
    NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of service.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-19 16:56 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia vGPU software and Cloud Gaming Affected: All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release
    Create a notification for this product.
    nvidia virtual_gpu Affected: 0 , < 13.11 (custom)
    Affected: 14.0 , < 16.6 (custom)
    Affected: 17.0 , < 17.2 (custom)
        cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia cloud_gaming_virtual_gpu Affected: 0 , < 555.52.04 (custom)
        cpe:2.3:a:nvidia:cloud_gaming_virtual_gpu:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:15.760Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "virtual_gpu",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "13.11",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "16.6",
                    "status": "affected",
                    "version": "14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "17.2",
                    "status": "affected",
                    "version": "17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:cloud_gaming_virtual_gpu:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "cloud_gaming_virtual_gpu",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.52.04",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0085",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-19T16:56:23.736265Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-19T17:00:44.334Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "vGPU software and Cloud Gaming",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of service."
                }
              ],
              "value": "NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of service."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Data tampering, escalation of privileges, denial of service"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-266",
                  "description": "CWE-266",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T21:23:31.505Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0085",
        "datePublished": "2024-06-13T21:23:31.505Z",
        "dateReserved": "2023-12-02T00:41:56.027Z",
        "dateUpdated": "2024-08-19T17:00:44.334Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0084 (GCVE-0-2024-0084)

    Vulnerability from cvelistv5 – Published: 2024-06-13 21:23 – Updated: 2024-08-01 17:41
    VLAI
    Title
    CVE
    Summary
    NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could execute privileged operations. A successful exploit of this vulnerability might lead to information disclosure, data tampering, escalation of privileges, and denial of service.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-14 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia vGPU software and Cloud Gaming Affected: All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release
    Create a notification for this product.
    nvidia virtual_gpu_graphics_driver Affected: 0 , < 13.11 (custom)
    Affected: 0 , < 16.6 (custom)
    Affected: 0 , < 17.2 (custom)
        cpe:2.3:a:nvidia:virtual_gpu_graphics_driver:13.10:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:virtual_gpu_graphics_driver:13.10:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "virtual_gpu_graphics_driver",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "13.11",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "16.6",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "17.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0084",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-15T03:55:37.767Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:15.927Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "vGPU software and Cloud Gaming",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could execute privileged operations. A successful exploit of this vulnerability might lead to information disclosure, data tampering, escalation of privileges, and denial of service."
                }
              ],
              "value": "NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could execute privileged operations. A successful exploit of this vulnerability might lead to information disclosure, data tampering, escalation of privileges, and denial of service."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Information disclosure, data tampering, escalation of privileges, denial of service"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-250",
                  "description": "CWE-250",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T21:23:31.105Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0084",
        "datePublished": "2024-06-13T21:23:31.105Z",
        "dateReserved": "2023-12-02T00:41:55.036Z",
        "dateUpdated": "2024-08-01T17:41:15.927Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0092 (GCVE-0-2024-0092)

    Vulnerability from cvelistv5 – Published: 2024-06-13 21:23 – Updated: 2024-08-01 17:41
    VLAI
    Title
    CVE
    Summary
    NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of exception conditions might lead to denial of service.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-17 16:45 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia GPU display driver, vGPU software, and Cloud Gaming Affected: All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0092",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-17T16:45:14.826848Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-17T16:45:23.624Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:15.947Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU display driver, vGPU software, and Cloud Gaming",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of exception conditions might lead to denial of service."
                }
              ],
              "value": "NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of exception conditions might lead to denial of service."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Denial of service"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-703",
                  "description": "CWE-703",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T21:23:30.327Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0092",
        "datePublished": "2024-06-13T21:23:30.327Z",
        "dateReserved": "2023-12-02T00:42:01.816Z",
        "dateUpdated": "2024-08-01T17:41:15.947Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0093 (GCVE-0-2024-0093)

    Vulnerability from cvelistv5 – Published: 2024-06-13 21:23 – Updated: 2024-08-19 17:01
    VLAI
    Title
    CVE
    Summary
    NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerability might lead to information disclosure.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-19 17:01 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia vGPU software and Cloud Gaming Affected: All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:16.016Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0093",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-19T17:01:41.169385Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-19T17:01:50.663Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "vGPU software and Cloud Gaming",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerability might lead to information disclosure."
                }
              ],
              "value": "NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerability might lead to information disclosure."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Information disclosure"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "CWE-200",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T21:23:29.967Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0093",
        "datePublished": "2024-06-13T21:23:29.967Z",
        "dateReserved": "2023-12-02T00:42:02.964Z",
        "dateUpdated": "2024-08-19T17:01:50.663Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0091 (GCVE-0-2024-0091)

    Vulnerability from cvelistv5 – Published: 2024-06-13 21:23 – Updated: 2024-08-01 17:41
    VLAI
    Title
    CVE
    Summary
    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-14 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia GPU display driver, vGPU software, and Cloud Gaming Affected: All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release
    Create a notification for this product.
    nvidia geforce Affected: 0 , < 555.99 (custom)
        cpe:2.3:a:nvidia:geforce:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia studio Affected: 0 , < 555.99 (custom)
        cpe:2.3:a:nvidia:studio:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia quadro_firmware Affected: 0 , < 555.99 (custom)
    Affected: 0 , < 552.55 (custom)
        cpe:2.3:a:nvidia:quadro_firmware:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia nvs_firmware Affected: 0 , < 555.99 (custom)
    Affected: 0 , < 552.55 (custom)
        cpe:2.3:a:nvidia:nvs_firmware:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia rtx Affected: 0 , < 555.99 (custom)
    Affected: 0 , < 552.55 (custom)
        cpe:2.3:a:nvidia:rtx:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia tesla Affected: 0 , < 552.55 (custom)
        cpe:2.3:a:nvidia:tesla:552.55:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:geforce:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "geforce",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:studio:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "studio",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:quadro_firmware:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "quadro_firmware",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "552.55",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:nvs_firmware:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "nvs_firmware",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "552.55",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:rtx:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "rtx",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "552.55",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:tesla:552.55:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "tesla",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "552.55",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0091",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-15T03:55:35.767Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:15.985Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU display driver, vGPU software, and Cloud Gaming",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering."
                }
              ],
              "value": "NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Denial of service, information disclosure, data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-822",
                  "description": "CWE-822",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T21:23:29.556Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0091",
        "datePublished": "2024-06-13T21:23:29.556Z",
        "dateReserved": "2023-12-02T00:42:00.978Z",
        "dateUpdated": "2024-08-01T17:41:15.985Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0089 (GCVE-0-2024-0089)

    Vulnerability from cvelistv5 – Published: 2024-06-13 21:23 – Updated: 2024-08-01 17:41
    VLAI
    Title
    CVE
    Summary
    NVIDIA GPU Display Driver for Windows contains a vulnerability where the information from a previous client or another process could be disclosed. A successful exploit of this vulnerability might lead to code execution, information disclosure, or data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-15 03:55 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia GPU display driver, vGPU software, and Cloud Gaming Affected: All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release
    Create a notification for this product.
    nvidia geforce Affected: 0 , < 555.99 (custom)
        cpe:2.3:a:nvidia:geforce:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia studio Affected: 0 , < 555.99 (custom)
        cpe:2.3:a:nvidia:studio:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia quadro_firmware Affected: 0 , < 555.99 (custom)
    Affected: 0 , < 552.55 (custom)
        cpe:2.3:a:nvidia:quadro_firmware:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia nvs_firmware Affected: 0 , < 555.99 (custom)
    Affected: 0 , < 552.55 (custom)
        cpe:2.3:a:nvidia:nvs_firmware:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia rtx Affected: 0 , < 555.99 (custom)
    Affected: 0 , < 552.55 (custom)
        cpe:2.3:a:nvidia:rtx:555.99:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia tesla Affected: 0 , < 552.55 (custom)
        cpe:2.3:a:nvidia:tesla:552.55:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:geforce:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "geforce",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:studio:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "studio",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:quadro_firmware:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "quadro_firmware",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "552.55",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:nvs_firmware:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "nvs_firmware",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "552.55",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:rtx:555.99:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "rtx",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "555.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "552.55",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:tesla:552.55:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "tesla",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThan": "552.55",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0089",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-15T03:55:35.510137Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-17T12:53:30.805Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:15.971Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU display driver, vGPU software, and Cloud Gaming",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability where the information from a previous client or another process could be disclosed. A successful exploit of this vulnerability might lead to code execution, information disclosure, or data tampering."
                }
              ],
              "value": "NVIDIA GPU Display Driver for Windows contains a vulnerability where the information from a previous client or another process could be disclosed. A successful exploit of this vulnerability might lead to code execution, information disclosure, or data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Code execution, information disclosure, data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-665",
                  "description": "CWE-665",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T21:23:29.198Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0089",
        "datePublished": "2024-06-13T21:23:29.198Z",
        "dateReserved": "2023-12-02T00:41:59.121Z",
        "dateUpdated": "2024-08-01T17:41:15.971Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0090 (GCVE-0-2024-0090)

    Vulnerability from cvelistv5 – Published: 2024-06-13 21:23 – Updated: 2024-08-01 17:41
    VLAI
    Title
    CVE
    Summary
    NVIDIA GPU driver for Windows and Linux contains a vulnerability where a user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-14 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    nvidia GPU display driver, vGPU software, and Cloud Gaming Affected: All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release
    Create a notification for this product.
    nvidia gpu_display_driver Affected: 0 , ≤ 17.1 (custom)
    Affected: 0 , ≤ 16.5 (custom)
    Affected: 0 , ≤ 13.10 (custom)
        cpe:2.3:a:nvidia:gpu_display_driver:-:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia virtual_gpu Affected: 0 , ≤ 16.5 (custom)
    Affected: 0 , ≤ 17.1 (custom)
    Affected: 0 , ≤ 13.10 (custom)
        cpe:2.3:a:nvidia:virtual_gpu:-:*:*:*:*:*:*:*
    Create a notification for this product.
    nvidia cloud_gaming Affected: 0 , ≤ 13.10 (custom)
    Affected: 0 , ≤ 17.1 (custom)
    Affected: 0 , ≤ 16.5 (custom)
        cpe:2.3:a:nvidia:cloud_gaming:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:gpu_display_driver:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "gpu_display_driver",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThanOrEqual": "17.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "16.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "13.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:virtual_gpu:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "virtual_gpu",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThanOrEqual": "16.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "17.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "13.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nvidia:cloud_gaming:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "cloud_gaming",
                "vendor": "nvidia",
                "versions": [
                  {
                    "lessThanOrEqual": "13.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "17.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "16.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0090",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-15T03:55:33.792Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:15.818Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GPU display driver, vGPU software, and Cloud Gaming",
              "vendor": "nvidia",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": true,
                  "type": "text/html",
                  "value": "NVIDIA GPU driver for Windows and Linux contains a vulnerability where a user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering."
                }
              ],
              "value": "NVIDIA GPU driver for Windows and Linux contains a vulnerability where a user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Code execution, denial of service, escalation of privileges, information disclosure, data tampering"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T21:23:28.800Z",
            "orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
            "shortName": "nvidia"
          },
          "references": [
            {
              "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
        "assignerShortName": "nvidia",
        "cveId": "CVE-2024-0090",
        "datePublished": "2024-06-13T21:23:28.800Z",
        "dateReserved": "2023-12-02T00:41:59.934Z",
        "dateUpdated": "2024-08-01T17:41:15.818Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }