Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-3625


The NVIDIA GPU driver for FreeBSD R352 before 352.09, 346 before 346.72, R349 before 349.16, R343 before 343.36, R340 before 340.76, R337 before 337.25, R334 before 334.21, R331 before 331.113, and R304 before 304.125 allows local users with certain permissions to read or write arbitrary kernel memory via unspecified vectors that trigger an untrusted pointer dereference.


Published

2015-07-18T00:59:00.093

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.2 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nvidia gpu_driver < 304.125 Yes
Application nvidia gpu_driver < 331.113 Yes
Application nvidia gpu_driver < 334.21 Yes
Application nvidia gpu_driver < 337.25 Yes
Application nvidia gpu_driver < 340.76 Yes
Application nvidia gpu_driver < 343.36 Yes
Application nvidia gpu_driver < 346.72 Yes
Application nvidia gpu_driver < 349.16 Yes
Application nvidia gpu_driver < 352.09 Yes
Operating System freebsd freebsd * No

References