Show filters
638 Total Results
Displaying 261-270 of 638
Sort by:
Attacker Value
Unknown
CVE-2022-31600
Disclosure Date: July 04, 2022 (last updated February 24, 2025)
NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmmCore, where a user with high privileges can chain another vulnerability to this vulnerability, causing an integer overflow, possibly leading to code execution, escalation of privileges, denial of service, compromised integrity, and information disclosure. The scope of impact can extend to other components.
0
Attacker Value
Unknown
CVE-2022-31599
Disclosure Date: July 04, 2022 (last updated February 24, 2025)
NVIDIA DGX A100 contains a vulnerability in SBIOS in the Ofbd, where a local user with elevated privileges can cause access to an uninitialized pointer, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.
0
Attacker Value
Unknown
CVE-2022-28200
Disclosure Date: July 02, 2022 (last updated February 24, 2025)
NVIDIA DGX A100 contains a vulnerability in SBIOS in the BiosCfgTool, where a local user with elevated privileges can read and write beyond intended bounds in SMRAM, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.
0
Attacker Value
Unknown
CVE-2022-31605
Disclosure Date: July 01, 2022 (last updated February 24, 2025)
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load(). The deserialization of Untrusted Data, may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.
0
Attacker Value
Unknown
CVE-2022-31604
Disclosure Date: July 01, 2022 (last updated February 24, 2025)
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pickle and no safe deserialization. The deserialization of Untrusted Data may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.
0
Attacker Value
Unknown
CVE-2022-28192
Disclosure Date: May 17, 2022 (last updated February 23, 2025)
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may lead to a use-after-free, which in turn may cause denial of service. This attack is complex to carry out because the attacker needs to have control over freeing some host side resources out of sequence, which requires elevated privileges.
0
Attacker Value
Unknown
CVE-2022-28191
Disclosure Date: May 17, 2022 (last updated February 23, 2025)
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where uncontrolled resource consumption can be triggered by an unprivileged regular user, which may lead to denial of service.
0
Attacker Value
Unknown
CVE-2022-28190
Disclosure Date: May 17, 2022 (last updated February 23, 2025)
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where improper input validation can cause denial of service.
0
Attacker Value
Unknown
CVE-2022-28189
Disclosure Date: May 17, 2022 (last updated February 23, 2025)
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a NULL pointer dereference may lead to a system crash.
0
Attacker Value
Unknown
CVE-2022-28188
Disclosure Date: May 17, 2022 (last updated February 23, 2025)
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the product receives input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly, which may lead to denial of service.
0