imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2006-1523
Alta 10.0

The __group_complete_signal function in the RCU signal handling (signal.c) in Linux kernel 2.6.16, and possibly other versions, has unknown impact and attack vectors related to improper use of BUG_ON.

linux linux_kernel
0.03EPSS
CVE-2013-7470
Media 5.9

cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstrated by icmpsic, a different vulnerability than CVE-2013-0310…

linux linux_kernel
0.03EPSS
CVE-2006-6304
Alta 7.5

The do_coredump function in fs/exec.c in the Linux kernel 2.6.19 sets the flag variable to O_EXCL but does not use it, which allows context-dependent attackers to modify arbitrary files via a rewrite attack during a core dump.

linux linux_kernel
0.03EPSS
CVE-2023-38432
Critica 9.1

An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read.

linux linux_kernel · netapp h300s · netapp h410s · netapp h500s · e altri 3
0.03EPSS
CVE-2018-14617
Media 5.5

An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference and panic in hfsplus_lookup() in fs/hfsplus/dir.c when opening a file (that is purportedly a hard link) in an hfs+ filesystem that has malformed catalog data, and …

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.03EPSS
CVE-2018-14610
Media 5.5

An issue was discovered in the Linux kernel through 4.17.10. There is out-of-bounds access in write_extent_buffer() when mounting and operating a crafted btrfs image, because of a lack of verification that each block group has a corresponding chunk at mount ti…

linux linux_kernel
0.03EPSS
CVE-2010-4526
Alta 7.1

Race condition in the sctp_icmp_proto_unreachable function in net/sctp/input.c in Linux kernel 2.6.11-rc2 through 2.6.33 allows remote attackers to cause a denial of service (panic) via an ICMP unreachable message to a socket that is already locked by a user, …

linux linux_kernel · redhat enterprise_mrg · vmware esx
0.03EPSS
CVE-2018-14611
Media 5.5

An issue was discovered in the Linux kernel through 4.17.10. There is a use-after-free in try_merge_free_space() when mounting a crafted btrfs image, because of a lack of chunk type flag checks in btrfs_check_chunk_valid in fs/btrfs/volumes.c.

debian debian_linux · linux linux_kernel
0.03EPSS
CVE-2023-32258
Alta 8.1

A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_LOGOFF and SMB2_CLOSE commands. The issue results from the lack of proper locking when performing operations on an obj…

linux linux_kernel · netapp h300s · netapp h410s · netapp h500s · e altri 1
0.03EPSS
CVE-2018-14613
Media 5.5

An issue was discovered in the Linux kernel through 4.17.10. There is an invalid pointer dereference in io_ctl_map_page() when mounting and operating a crafted btrfs image, because of a lack of block group item validation in check_leaf_item in fs/btrfs/tree-ch…

linux linux_kernel
0.03EPSS
CVE-2010-2243
Alta 7.5

A vulnerability exists in kernel/time/clocksource.c in the Linux kernel before 2.6.34 where on non-GENERIC_TIME systems (GENERIC_TIME=n), accessing /sys/devices/system/clocksource/clocksource0/current_clocksource results in an OOPS.

linux linux_kernel
0.03EPSS
CVE-2019-18814
Critica 9.8

An issue was discovered in the Linux kernel through 5.3.9. There is a use-after-free when aa_label_parse() fails in aa_audit_rule_init() in security/apparmor/audit.c.

linux linux_kernel
0.03EPSS
CVE-2015-8104
Critica 10.0

The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · oracle solaris · e altri 2
0.03EPSS
CVE-2018-13099
Media 5.5

An issue was discovered in fs/f2fs/inline.c in the Linux kernel through 4.4. A denial of service (out-of-bounds memory access and BUG) can occur for a modified f2fs filesystem image in which an inline inode contains an invalid reserved blkaddr.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse leap
0.03EPSS
CVE-1999-0061
Media 5.1

File creation and deletion, and remote execution, in the BSD line printer daemon (lpd).

bsdi bsd_os · freebsd freebsd · linux linux_kernel · openbsd openbsd
0.02EPSS
CVE-2002-0510
Media 5.0

The UDP implementation in Linux 2.4.x kernels keeps the IP Identification field at 0 for all non-fragmented packets, which could allow remote attackers to determine that a target system is running Linux.

linux linux_kernel
0.02EPSS
CVE-2015-3636
Media 4.9

The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data structure during an unhash operation, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · redhat enterprise_linux
0.02EPSS
CVE-2019-19770
Alta 8.2

In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (which is used to remove a file or directory in debugfs that was previously created with a call to another debugfs function such as debugfs_creat…

linux linux_kernel
0.02EPSS
CVE-2001-1056
Alta 7.5

IRC DCC helper in the ip_masq_irc IP masquerading module 2.2 allows remote attackers to bypass intended firewall restrictions by causing the target system to send a "DCC SEND" request to a malicious server which listens on port 6667, which may cause the module…

linux linux_kernel
0.02EPSS
CVE-2004-0077
Alta 7.2

The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to …

linux linux_kernel · netwosix netwosix_linux · redhat bigmem_kernel · redhat kernel · e altri 3
0.02EPSS
CVE-2020-25645
Alta 7.5

A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints t…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp hci_compute_node_bios · e altri 3
0.02EPSS
CVE-2014-2309
Media 6.1

The ip6_route_add function in net/ipv6/route.c in the Linux kernel through 3.13.6 does not properly count the addition of routes, which allows remote attackers to cause a denial of service (memory consumption) via a flood of ICMPv6 Router Advertisement packets…

linux linux_kernel · opensuse opensuse · suse linux_enterprise_server
0.02EPSS
CVE-2005-0177
Alta 7.8

nls_ascii.c in Linux before 2.6.8.1 uses an incorrect table size, which allows attackers to cause a denial of service (kernel crash) via a buffer overflow.

linux linux_kernel
0.02EPSS
CVE-2021-3178
Media 6.5

fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some parties argue that such a subdirectory export …

debian debian_linux · fedoraproject fedora · linux linux_kernel
0.02EPSS
CVE-2010-0298
Media 6.5

The x86 emulator in KVM 83 does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) in determining the memory access available to CPL3 code, which allows guest OS users to cause a denial of service (guest OS crash) or gain privileges on th…

debian debian_linux · linux linux_kernel
0.02EPSS