6.9

CVE-2015-5950

The NVIDIA display driver R352 before 353.82 and R340 before 341.81 on Windows; R304 before 304.128, R340 before 340.93, and R352 before 352.41 on Linux; and R352 before 352.46 on GRID vGPU and vSGA allows local users to write to an arbitrary kernel memory location and consequently gain privileges via a crafted ioctl call.

Data is provided by the National Vulnerability Database (NVD)
NvidiaGpu Driver Version <= 352.30
NvidiaDisplay Driver SwPlatformlinux Version <= 352.09
NvidiaDisplay Driver Version304.108 SwPlatformlinux
NvidiaDisplay Driver Version304.119 SwPlatformlinux
NvidiaDisplay Driver Version304.121 SwPlatformlinux
NvidiaDisplay Driver Version304.123 SwPlatformlinux
NvidiaDisplay Driver Version304.125 SwPlatformlinux
NvidiaDisplay Driver Version352.21 SwPlatformlinux
NvidiaDisplay Driver Version352.30 SwPlatformlinux
NvidiaDisplay Driver Version <= 352.86
   MicrosoftWindows
NvidiaDisplay Driver Version340.43
   MicrosoftWindows
NvidiaDisplay Driver Version340.52
   MicrosoftWindows
NvidiaDisplay Driver Version341.44
   MicrosoftWindows
NvidiaDisplay Driver Version353.06
   MicrosoftWindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.137
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.