QSearchQSearch

CVE-2021-39158

8.8 HIGH

NVCaffe's python required dependencies list used to contain `gfortran`version prior to 0.17.4, entry which does not exist in the reposito...

Published: 2021-08-23 · Last updated: 2026-06-17

Severity and scoring

CVSS
8.8 HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE
CWE-345

Affected products

VendorProduct
nvidianvcaffe

Description

NVCaffe's python required dependencies list used to contain `gfortran`version prior to 0.17.4, entry which does not exist in the repository pypi.org. An attacker could potentially have posted malicious files to pypi.org causing a user to install it within NVCaffe.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-24228 NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data (7.8 HIGH)
  • CVE-2026-24155 NVIDIA NeMo Framework for all platforms contains a code injection vulnerability (7.8 HIGH)
  • CVE-2026-24237 NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data (7.8 HIGH)
  • CVE-2026-24221 NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data (7.8 HIGH)
  • CVE-2026-24199 NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could cause a race condition by reordering comp... (4.7 MEDIUM)

Same CWE

  • CVE-2026-53862 OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with... (4.2 MEDIUM)
  • CVE-2026-53900 Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a mali... (4.3 MEDIUM)
  • CVE-2026-53899 Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to rece... (6.5 MEDIUM)
  • CVE-2026-47777 Mastodon is a free, open-source social network server based on ActivityPub (7.5 HIGH)
  • CVE-2026-53406 Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an au... (7.8 HIGH)