
CVE-2025-23360
https://notcve.org/view.php?id=CVE-2025-23360
11 Mar 2025 — NVIDIA Nemo Framework contains a vulnerability where a user could cause a relative path traversal issue by arbitrary file write. A successful exploit of this vulnerability may lead to code execution and data tampering. • https://nvidia.custhelp.com/app/answers/detail/a_id/5623 • CWE-23: Relative Path Traversal •

CVE-2024-0129
https://notcve.org/view.php?id=CVE-2024-0129
15 Oct 2024 — NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extraction. A successful exploit of this vulnerability may lead to code execution and data tampering. • https://nvidia.custhelp.com/app/answers/detail/a_id/5580 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2024-0081
https://notcve.org/view.php?id=CVE-2024-0081
05 Apr 2024 — NVIDIA NeMo framework for Ubuntu contains a vulnerability in tools/asr_webapp where an attacker may cause an allocation of resources without limits or throttling. A successful exploit of this vulnerability may lead to a server-side denial of service. El framework NVIDIA NeMo para Ubuntu contiene una vulnerabilidad en tools/asr_webapp donde un atacante puede provocar una asignación de recursos sin límites ni estrangulaciones. Una explotación exitosa de esta vulnerabilidad puede provocar una denegación de ser... • https://github.com/NVIDIA/NeMo/security/advisories/GHSA-x392-p65g-4rxx • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2022-22821
https://notcve.org/view.php?id=CVE-2022-22821
08 Jan 2022 — NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in which ../ Path Traversal may lead to deletion of any directory when admin privileges are available. NVIDIA NeMo versiones anteriores a 1.6.0, contiene una vulnerabilidad en ASR WebApp, en la que el Salto de Ruta ../ puede conllevar a una eliminación de cualquier directorio cuando dispone de privilegios de administrador • https://github.com/NVIDIA/NeMo/security/advisories/GHSA-rpx7-33j2-xx9x • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •