Geforce Experience

Vendor:

First CVE: Nov 8, 2016 · Active for 9 years

37
Total CVEs
More Total CVEs than 97% of tracked products
5.3
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Geforce Experience over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 2016
9 years ago
Most Recent CVE
Feb 12, 2023
1,259 days ago

CVE Severity & Scoring

Geforce Experience37 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local34 (91.9%)
Network3 (8.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (81.1%)
High7 (18.9%)
Unknown0 (0.0%)
User Interaction
None27 (73.0%)
Unknown0 (0.0%)
Required10 (27.0%)
Privileges Required
Low28 (75.7%)
High2 (5.4%)
None7 (18.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Oct 4, 20179.885NOYES
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before GFE 3.1.0.52 contains a vulnerability in the kernel mode laye
Nov 8, 20168.831NOYES
NVIDIA GeForce Experience, all versions prior to 3.23, contains a vulnerability in the login flow when a user tries to log in by using a browser, while, at the same time, any other
Jun 25, 20218.327NONO
NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, wh
Dec 23, 20218.226NONO
NVIDIA GeForce Experience, all versions prior to 3.20.2, contains a vulnerability when GameStream is enabled in which an attacker with local system access can corrupt a system file
Dec 24, 20197.826NONO
NVIDIA GeForce Experience, all versions prior to 3.20.0.118, contains a vulnerability when GameStream is enabled in which an attacker with local system access can load the Intel gr
Nov 9, 20197.825NONO
NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows in which an attacker who has access to a local user account can plant a malicious dynami
Nov 27, 20187.825NONO
For the NVIDIA Quadro, NVS, and GeForce products, GFE GameStream and NVTray Plugin unquoted service path vulnerabilities are examples of the unquoted service path vulnerability in
Nov 8, 20167.825NONO
NVIDIA GeForce Experience before 3.18 contains a vulnerability when ShadowPlay or GameStream is enabled. When an attacker has access to the system and creates a hard link, the soft
Mar 28, 20197.024NONO
NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 during application installation on Windows 7 in elevated privilege mode, where a local user who ini
Nov 27, 20187.824NONO

Exploit Exposure

Signals from CVEs in this product scope (37 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
5.4% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (37 CVEs).

Media Mentions

Signals from CVEs in this product scope (37 CVEs).

Top CNAs Publishing CVEs For Geforce Experience

Top CWEs

Versions

No cataloged versions.