imPC@ndo IT

Linux vulnerabilities

14.775 CVE

CVE-2016-6758
High 7.8

An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to eleva…

linux linux_kernel
0.02EPSS
CVE-2014-2739
Medium 4.6

The cma_req_handler function in drivers/infiniband/core/cma.c in the Linux kernel 3.14.x through 3.14.1 attempts to resolve an RDMA over Converged Ethernet (aka RoCE) address that is properly resolved within a different module, which allows remote attackers to…

linux linux_kernel
0.02EPSS
CVE-2021-26708
High 7.0

A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were implicitly introduced in the commits that …

linux linux_kernel · netapp aff_baseboard_management_controller · netapp baseboard_management_controller_500f_firmware · netapp baseboard_management_controller_a250_firmware · and 5 more
0.02EPSS
CVE-2016-8465
High 7.0

An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged proc…

linux linux_kernel
0.02EPSS
CVE-2016-8437
Critical 9.8

Improper input validation in Access Control APIs. Access control API may return memory range checking incorrectly. Product: Android. Versions: Kernel 3.18. Android ID: A-31623057. References: QC-CR#1009695.

linux linux_kernel
0.02EPSS
CVE-2016-8398
Critical 9.8

Unauthenticated messages processed by the UE. Certain NAS messages are processed when no EPS security context exists in the UE. Product: Android. Versions: Kernel 3.18. Android ID: A-31548486. References: QC-CR#877705.

linux linux_kernel
0.02EPSS
CVE-2004-0186
High 7.2

smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.

linux linux_kernel · samba samba
0.02EPSS
CVE-2015-3214
Medium 6.9

The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.…

arista eos · debian debian_linux · lenovo emc_px12-400r_ivx · lenovo emc_px12-450r_ivx · and 15 more
0.02EPSS
CVE-2017-6264
High 7.8

An elevation of privilege vulnerability exists in the NVIDIA GPU driver (gm20b_clk_throt_set_cdev_state), where an out of bound memory read is used as a function pointer could lead to code execution in the kernel.This issue is rated as high because it could al…

linux linux_kernel
0.02EPSS
CVE-2021-4157
High 8.0

An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system …

fedoraproject fedora · linux linux_kernel · netapp h300e_firmware · netapp h300s_firmware · and 6 more
0.02EPSS
CVE-2003-0127
High 7.2

The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.

linux linux_kernel
0.02EPSS
CVE-2022-1199
High 7.5

A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability.

linux linux_kernel · netapp active_iq_unified_manager · netapp h300s_firmware · netapp h410c_firmware · and 4 more
0.02EPSS
CVE-2017-0458
High 7.0

An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process…

linux linux_kernel
0.02EPSS
CVE-2016-9793
High 7.8

The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified oth…

linux linux_kernel
0.02EPSS
CVE-2017-0613
High 7.0

An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first require…

linux linux_kernel
0.02EPSS
CVE-2021-42008
High 7.8

The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access.

debian debian_linux · linux linux_kernel · netapp h300e_firmware · netapp h300s_firmware · and 7 more
0.02EPSS
CVE-2013-0268
Medium 6.2

The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended capability restrictions by executing a crafted application as root, as demonstrated by msr32.c.

linux linux_kernel
0.02EPSS
CVE-1999-0183
Medium 6.4

Linux implementations of TFTP would allow access to files outside the restricted directory.

linux linux_kernel · tftp tftp
0.02EPSS
CVE-2016-8405
Medium 4.7

An information disclosure vulnerability in kernel components including the ION subsystem, Binder, USB driver and networking subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate be…

linux linux_kernel
0.02EPSS
CVE-1999-0656
Medium 5.0

The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.

linux linux_kernel
0.02EPSS
CVE-2023-6536
Medium 6.5

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel…

debian debian_linux · linux linux_kernel · redhat codeready_linux_builder_eus · redhat codeready_linux_builder_eus_for_power_little_endian_eus · and 13 more
0.02EPSS
CVE-2023-6535
Medium 6.5

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel…

linux linux_kernel · redhat codeready_linux_builder_eus · redhat codeready_linux_builder_eus_for_power_little_endian_eus · redhat codeready_linux_builder_for_arm64_eus · and 12 more
0.02EPSS
CVE-2017-0524
High 7.0

An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged p…

linux linux_kernel
0.02EPSS
CVE-2017-0519
High 7.0

An elevation of privilege vulnerability in the Qualcomm fingerprint sensor driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privil…

linux linux_kernel
0.02EPSS
CVE-2017-0456
High 7.0

An elevation of privilege vulnerability in the Qualcomm IPA driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. P…

linux linux_kernel
0.02EPSS