CVE-2007-3532 describes a vulnerability in NVIDIA drivers, specifically versions prior to 1.0.7185, 1.0.9639, and 100.14.11, affecting Gentoo Linux and potentially other distributions. The flaw involves insecure permissions on /dev/nvidia* device files, allowing local users to modify video card settings, cause denial of service (including physical damage), and access sensitive information. With a CVSS score of 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C), this vulnerability has a high severity, indicating that a local attacker with low complexity can achieve complete confidentiality, integrity, and availability impact. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.7185CPE matchmatch criteria | cpe:2.3:a:nvidia:video_driver:*:*:*:*:*:*:*:* | ||
<= 1.0.9639CPE matchmatch criteria | cpe:2.3:a:nvidia:video_driver:*:*:*:*:*:*:*:* | ||
<= 100.14.11CPE matchmatch criteria | cpe:2.3:a:nvidia:video_driver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.