5.5
CVE-2024-0147 -
NVIDIA GPU display driver for Windows and Linux contains a vulnerability where referencing memory after it has been freed can lead to denial of service or data tampering.
7.1
CVE-2024-0150 -
NVIDIA GPU display driver for Windows and Linux contains a vulnerability where data is written past the end or before the beginning of a buffer. A successful exploit of this vulnerability might lead to information disclosure, denial of service, or data tampering.
6.8
CVE-2024-0140 -
NVIDIA RAPIDS contains a vulnerability in cuDF and cuML, where a user could cause a deserialization of untrusted data issue. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
5.5
CVE-2024-0137 - nvidia-container-toolkit: Improper Isolation or Compartmentalization in NVIDIA Container Toolkit
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code running in the hostβs network namespace. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful β¦
7.6
CVE-2024-0136 - nvidia-container-toolkit: Improper Isolation or Compartmentalization in NVIDIA Container Toolkit
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A sucβ¦
7.6
CVE-2024-0135 - nvidia-container-toolkit: Improper Isolation or Compartmentalization in NVIDIA Container Toolkit
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, anβ¦
4
CVE-2024-22315 - IBM Fusion improper communication restriction
IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker who gains access to a Fusion container to establish an external network connection.
7.5
CVE-2025-22865 - ParsePKCS1PrivateKey panic with partial keys in crypto/x509
Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT values would panic when verifying that the key is well formed.
8.8
CVE-2024-45340 - GOAUTH credential leak in cmd/go
Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server to request credentials they should not have access to. By default, unless otherwise set, this only affected credentials stored in the users .netrc file.
7.1
CVE-2024-45339 - Vulnerability when creating log files in github.com/golang/glog
When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and overwrite that senβ¦