imPC@ndo EN

Vulnerabilità Linux

14.774 CVE

CVE-2019-19048
Alta 7.5

A memory leak in the crypto_reportstat() function in drivers/virt/vboxguest/vboxguest_utils.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering copy_form_user() failures, aka CID-e0b0cb938864.

canonical ubuntu_linux · linux linux_kernel
0.04EPSS
CVE-2003-1604
Alta 7.5

The redirect_target function in net/ipv4/netfilter/ipt_REDIRECT.c in the Linux kernel before 2.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending packets to an interface that has a 0.0.0.0 IP address, a rela…

linux linux_kernel
0.04EPSS
CVE-2014-7284
Media 6.4

The net_get_random_once implementation in net/core/utils.c in the Linux kernel 3.13.x and 3.14.x before 3.14.5 on certain Intel processors does not perform the intended slow-path operation to initialize random seeds, which makes it easier for remote attackers …

linux linux_kernel
0.04EPSS
CVE-2022-1043
Alta 8.8

A flaw was found in the Linux kernel’s io_uring implementation. This flaw allows an attacker with a local account to corrupt system memory, crash the system or escalate privileges.

linux linux_kernel
0.04EPSS
CVE-2010-2959
Alta 7.2

Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows attackers to execute arbitrary code or cause a …

debian debian_linux · fedoraproject fedora · linux linux_kernel · opensuse opensuse · e altri 4
0.04EPSS
CVE-2002-2438
Alta 7.5

TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linux TCP stack after firewalling.

linux linux_kernel
0.04EPSS
CVE-2010-3873
Media 5.0

The X.25 implementation in the Linux kernel before 2.6.36.2 does not properly parse facilities, which allows remote attackers to cause a denial of service (heap memory corruption and panic) or possibly have unspecified other impact via malformed (1) X25_FAC_CA…

debian debian_linux · linux linux_kernel · opensuse opensuse · suse linux_enterprise_server
0.04EPSS
CVE-2014-7145
Alta 7.8

The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer dereference and client system crash) or possibly have unspecified other impact by deleting the IPC$ share during…

canonical ubuntu_linux · linux linux_kernel · redhat enterprise_linux_desktop · redhat enterprise_linux_hpc_node · e altri 2
0.04EPSS
CVE-2016-2384
Media 4.6

Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (panic) or possibly have unspecified other impact via vectors involving an invali…

linux linux_kernel · novell suse_linux_enterprise_real_time_extension
0.04EPSS
CVE-2017-5123
Alta 8.8

Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.

linux linux_kernel · netapp cloud_backup · netapp h300e_firmware · netapp h300s_firmware · e altri 5
0.04EPSS
CVE-2005-2457
Media 5.0

The driver for compressed ISO file systems (zisofs) in the Linux kernel before 2.6.12.5 allows local users and remote attackers to cause a denial of service (kernel crash) via a crafted compressed ISO file system.

linux linux_kernel
0.04EPSS
CVE-2015-8215
Media 5.0

net/ipv6/addrconf.c in the IPv6 stack in the Linux kernel before 4.0 does not validate attempted changes to the MTU value, which allows context-dependent attackers to cause a denial of service (packet loss) via a value that is (1) smaller than the minimum comp…

linux linux_kernel
0.04EPSS
CVE-2008-4576
Alta 7.8

sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active transports and triggers the OOPS when t…

linux linux_kernel
0.04EPSS
CVE-2011-5327
Critica 9.8

In the Linux kernel before 3.1, an off by one in the drivers/target/loopback/tcm_loop.c tcm_loop_make_naa_tpg() function could result in at least memory corruption.

linux linux_kernel
0.04EPSS
CVE-2016-0728
Alta 7.8

The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-fr…

canonical ubuntu_linux · debian debian_linux · google android · hp server_migration_pack · e altri 1
0.04EPSS
CVE-2013-4247
Alta 7.8

Off-by-one error in the build_unc_path_to_root function in fs/cifs/connect.c in the Linux kernel before 3.9.6 allows remote attackers to cause a denial of service (memory corruption and system crash) via a DFS share mount operation that triggers use of an unex…

linux linux_kernel
0.04EPSS
CVE-2019-18680
Alta 7.5

An issue was discovered in the Linux kernel 4.4.x before 4.4.195. There is a NULL pointer dereference in rds_tcp_kill_sock() in net/rds/tcp.c that will cause denial of service, aka CID-91573ae4aed0.

linux linux_kernel
0.04EPSS
CVE-2017-11176
Alta 7.8

The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possibly have u…

debian debian_linux · linux linux_kernel
0.04EPSS
CVE-2006-4572
Alta 7.5

ip6_tables in netfilter in the Linux kernel before 2.6.16.31 allows remote attackers to (1) bypass a rule that disallows a protocol, via a packet with the protocol header not located immediately after the fragment header, aka "ip6_tables protocol bypass bug;" …

linux linux_kernel
0.04EPSS
CVE-2012-1583
Media 5.0

Double free vulnerability in the xfrm6_tunnel_rcv function in net/ipv6/xfrm6_tunnel.c in the Linux kernel before 2.6.22, when the xfrm6_tunnel module is enabled, allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets.

linux linux_kernel
0.04EPSS
CVE-2012-4444
Media 5.0

The ip6_frag_queue function in net/ipv6/reassembly.c in the Linux kernel before 2.6.36 allows remote attackers to bypass intended network restrictions via overlapping IPv6 fragments.

linux linux_kernel
0.04EPSS
CVE-2019-19060
Alta 7.5

A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_buffer.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-ab612b1daf41.

broadcom brocade_fabric_operating_system_firmware · canonical ubuntu_linux · linux linux_kernel · netapp active_iq_unified_manager · e altri 13
0.04EPSS
CVE-2010-1086
Alta 7.8

The ULE decapsulation functionality in drivers/media/dvb/dvb-core/dvb_net.c in dvb-core in Linux kernel 2.6.33 and earlier allows attackers to cause a denial of service (infinite loop) via a crafted MPEG2-TS frame, related to an invalid Payload Pointer ULE.

debian debian_linux · linux linux_kernel
0.04EPSS
CVE-2014-4323
Alta 7.5

The mdp_lut_hw_update function in drivers/video/msm/mdp.c in the MDP display driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate certain start and length valu…

linux linux_kernel
0.04EPSS
CVE-2010-4805
Alta 7.5

The socket implementation in net/core/sock.c in the Linux kernel before 2.6.35 does not properly manage a backlog of received packets, which allows remote attackers to cause a denial of service by sending a large amount of network traffic, related to the sk_ad…

linux linux_kernel · redhat enterprise_linux
0.04EPSS