Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-5053

Опубликовано: 24 нояб. 2015
Источник: nvd
CVSS2: 10
EPSS Низкий

Описание

The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for GRID vGPU and vSGA does not properly restrict access to third-party device IO memory, which allows attackers to gain privileges, cause a denial of service (resource consumption), or possibly have unspecified other impact via unknown vectors related to the follow_pfn kernel-mode API call.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:nvidia:gpu_driver:346.16:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:gpu_driver:346.22:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:gpu_driver:346.35:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:gpu_driver:346.47:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:gpu_driver:346.59:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:gpu_driver:346.72:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:gpu_driver:346.82:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:gpu_driver:352.09:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:gpu_driver:352.21:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:gpu_driver:352.30:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:gpu_driver:352.41:*:*:*:*:*:*:*

EPSS

Процентиль: 66%
0.00519
Низкий

10 Critical

CVSS2

Дефекты

CWE-284

Связанные уязвимости

ubuntu
около 10 лет назад

The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for GRID vGPU and vSGA does not properly restrict access to third-party device IO memory, which allows attackers to gain privileges, cause a denial of service (resource consumption), or possibly have unspecified other impact via unknown vectors related to the follow_pfn kernel-mode API call.

debian
около 10 лет назад

The host memory mapping path feature in the NVIDIA GPU graphics driver ...

github
больше 3 лет назад

The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for GRID vGPU and vSGA does not properly restrict access to third-party device IO memory, which allows attackers to gain privileges, cause a denial of service (resource consumption), or possibly have unspecified other impact via unknown vectors related to the follow_pfn kernel-mode API call.

fstec
около 10 лет назад

Уязвимость программного обеспечения графического процессора NVIDIA GPU, позволяющая нарушителю повысить свои привилегии или вызвать отказ в обслуживании

EPSS

Процентиль: 66%
0.00519
Низкий

10 Critical

CVSS2

Дефекты

CWE-284