Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-21821

Опубликовано: 29 мар. 2022
Источник: nvd
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a local user to download a specially crafted, corrupted file and locally execute cuobjdump against the file. Such an attack may lead to remote code execution that causes complete denial of service and an impact on data confidentiality and integrity.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:nvidia:cuda_toolkit:*:*:*:*:*:*:*:*
Версия до 11.6.2 (исключая)

Одно из

cpe:2.3:a:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 55%
0.00324
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-1285
CWE-190

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 4 года назад

NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a local user to download a specially crafted, corrupted file and locally execute cuobjdump against the file. Such an attack may lead to remote code execution that causes complete denial of service and an impact on data confidentiality and integrity.

CVSS3: 7.8
debian
почти 4 года назад

NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in ...

CVSS3: 7.8
github
почти 4 года назад

NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a local user to download a specially crafted, corrupted file and locally execute cuobjdump against the file. Such an attack may lead to remote code execution that causes complete denial of service and an impact on data confidentiality and integrity.

EPSS

Процентиль: 55%
0.00324
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-1285
CWE-190