Geforce Experience
Vendor:
First CVE: Nov 8, 2016 · Active for 9 years
37
Total CVEs
More Total CVEs than 97% of tracked products
5.3
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Geforce Experience over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 2016
9 years ago
Most Recent CVE
Feb 12, 2023
1,259 days ago
CVE Severity & Scoring
Geforce Experience37 CVEs
22%
70%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local34 (91.9%)
Network3 (8.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (81.1%)
High7 (18.9%)
Unknown0 (0.0%)
User Interaction
None27 (73.0%)
Unknown0 (0.0%)
Required10 (27.0%)
Privileges Required
Low28 (75.7%)
High2 (5.4%)
None7 (18.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14491CRITICAL Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. | Oct 4, 2017 | 9.8 | 85 | NO | YES |
CVE-2016-8812HIGH For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before GFE 3.1.0.52 contains a vulnerability in the kernel mode laye | Nov 8, 2016 | 8.8 | 31 | NO | YES |
CVE-2021-1073HIGH NVIDIA GeForce Experience, all versions prior to 3.23, contains a vulnerability in the login flow when a user tries to log in by using a browser, while, at the same time, any other | Jun 25, 2021 | 8.3 | 27 | NO | NO |
CVE-2021-23175HIGH NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, wh | Dec 23, 2021 | 8.2 | 26 | NO | NO |
CVE-2019-5702HIGH NVIDIA GeForce Experience, all versions prior to 3.20.2, contains a vulnerability when GameStream is enabled in which an attacker with local system access can corrupt a system file | Dec 24, 2019 | 7.8 | 26 | NO | NO |
CVE-2019-5701HIGH NVIDIA GeForce Experience, all versions prior to 3.20.0.118, contains a vulnerability when GameStream is enabled in which an attacker with local system access can load the Intel gr | Nov 9, 2019 | 7.8 | 25 | NO | NO |
CVE-2018-6263HIGH NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows in which an attacker who has access to a local user account can plant a malicious dynami | Nov 27, 2018 | 7.8 | 25 | NO | NO |
CVE-2016-3161HIGH For the NVIDIA Quadro, NVS, and GeForce products, GFE GameStream and NVTray Plugin unquoted service path vulnerabilities are examples of the unquoted service path vulnerability in | Nov 8, 2016 | 7.8 | 25 | NO | NO |
CVE-2019-5674HIGH NVIDIA GeForce Experience before 3.18 contains a vulnerability when ShadowPlay or GameStream is enabled. When an attacker has access to the system and creates a hard link, the soft | Mar 28, 2019 | 7.0 | 24 | NO | NO |
CVE-2018-6265HIGH NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 during application installation on Windows 7 in elevated privilege mode, where a local user who ini | Nov 27, 2018 | 7.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (37 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
5.4% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (37 CVEs).
Media Mentions
Signals from CVEs in this product scope (37 CVEs).
Top CNAs Publishing CVEs For Geforce Experience
Top CWEs
Versions
No cataloged versions.