7.5
CVSSv2

CVE-2014-8298

Published: 10/12/2014 Updated: 26/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R340.x before R340.65, R343.x before R343.36, and R346.x before R346.22, Linux for Tegra (L4T) driver before R21.2, and Chrome OS driver before R40 allows remote malicious users to cause a denial of service (segmentation fault and X server crash) or possibly execute arbitrary code via a crafted GLX indirect rendering protocol request.

Vulnerable Product Search on Vulmon Subscribe to Product

nvidia gpu driver r340.65

nvidia gpu driver r343.00

nvidia gpu driver r343.36

nvidia gpu driver r346.00

nvidia gpu driver r304.125

nvidia gpu driver r331.00

nvidia gpu driver r346.22

nvidia gpu driver r331.112

nvidia gpu driver r340.00

nvidia gpu driver

Vendor Advisories

Debian Bug report logs - #772972 src:nvidia-graphics-drivers*: CVE-2014-8298: GLX-INDIRECT (Including CVE-2014-8093, CVE-2014-8098) Package: src:nvidia-graphics-drivers-legacy-96xx; Maintainer for src:nvidia-graphics-drivers-legacy-96xx is (unknown); Reported by: Andreas Beckmann <anbe@debianorg> Date: Fri, 12 Dec 2014 16: ...