imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2016-2188
Media 4.6

The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descripto…

canonical ubuntu_linux · linux linux_kernel · novell suse_linux_enterprise_debuginfo · novell suse_linux_enterprise_desktop · e altri 6
0.02EPSS
CVE-2013-0343
Bassa 3.2

The ipv6_create_tempaddr function in net/ipv6/addrconf.c in the Linux kernel through 3.8 does not properly handle problems with the generation of IPv6 temporary addresses, which allows remote attackers to cause a denial of service (excessive retries and addres…

linux linux_kernel
0.02EPSS
CVE-2017-0325
Alta 7.0

An elevation of privilege vulnerability in the NVIDIA I2C HID driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process.…

linux linux_kernel
0.02EPSS
CVE-2018-1108
Media 5.9

kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.02EPSS
CVE-2015-8962
Alta 7.3

Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (memory corruption and system crash) by detaching a device during an SG_IO ioctl ca…

linux linux_kernel
0.02EPSS
CVE-2015-7515
Media 4.6

The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device that lacks endpoints.

linux linux_kernel
0.02EPSS
CVE-2017-7184
Alta 7.8

The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-o…

linux linux_kernel
0.02EPSS
CVE-2016-3136
Media 4.6

The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device without two interrupt-i…

canonical ubuntu_linux · linux linux_kernel · novell suse_linux_enterprise_desktop · novell suse_linux_enterprise_live_patching · e altri 5
0.02EPSS
CVE-2016-10290
Alta 7.0

An elevation of privilege vulnerability in the Qualcomm shared memory driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged …

linux linux_kernel
0.02EPSS
CVE-2016-10285
Alta 7.0

An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process.…

linux linux_kernel
0.02EPSS
CVE-2009-3234
Media 4.9

Buffer overflow in the perf_copy_attr function in kernel/perf_counter.c in the Linux kernel 2.6.31-rc1 allows local users to cause a denial of service (crash) and execute arbitrary code via a "big size data" to the perf_counter_open system call.

linux linux_kernel
0.02EPSS
CVE-2017-0521
Alta 7.0

An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process…

linux linux_kernel
0.02EPSS
CVE-2018-13097
Media 5.5

An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.17.3. There is an out-of-bounds read or a divide-by-zero error for an incorrect user_block_count in a corrupted f2fs image, leading to a denial of service (BUG).

linux linux_kernel
0.02EPSS
CVE-2016-6789
Alta 7.8

An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local …

linux linux_kernel
0.02EPSS
CVE-2016-6777
Alta 7.8

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromis…

linux linux_kernel
0.02EPSS
CVE-2016-6776
Alta 7.8

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromis…

linux linux_kernel
0.02EPSS
CVE-2016-6775
Alta 7.8

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromis…

linux linux_kernel
0.02EPSS
CVE-2016-3140
Media 4.6

The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device de…

canonical ubuntu_linux · linux linux_kernel · novell suse_linux_enterprise_debuginfo · novell suse_linux_enterprise_desktop · e altri 6
0.02EPSS
CVE-2016-3139
Media 4.6

The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor…

linux linux_kernel · novell suse_linux_enterprise_debuginfo · novell suse_linux_enterprise_desktop · novell suse_linux_enterprise_live_patching · e altri 5
0.02EPSS
CVE-2011-2942
Media 6.8

A certain Red Hat patch to the __br_deliver function in net/bridge/br_forward.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have un…

linux linux_kernel · redhat enterprise_linux
0.02EPSS
CVE-2005-1263
Alta 7.2

The elf_core_dump function in binfmt_elf.c for Linux kernel 2.x.x to 2.2.27-rc2, 2.4.x to 2.4.31-pre1, and 2.6.x to 2.6.12-rc4 allows local users to execute arbitrary code via an ELF binary that, in certain conditions involving the create_elf_tables function, …

linux linux_kernel
0.02EPSS
CVE-2019-3874
Media 6.5

The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp active_iq_unified_manager_for_vmware_vsphere · e altri 5
0.02EPSS
CVE-2019-15920
Media 4.3

An issue was discovered in the Linux kernel before 5.0.10. SMB2_read in fs/cifs/smb2pdu.c has a use-after-free. NOTE: this was not fixed correctly in 5.0.10; see the 5.0.11 ChangeLog, which documents a memory leak.

linux linux_kernel · opensuse leap
0.02EPSS
CVE-2016-8633
Media 6.8

drivers/firewire/net.c in the Linux kernel before 4.8.7, in certain unusual hardware configurations, allows remote attackers to execute arbitrary code via crafted fragmented packets.

linux linux_kernel
0.02EPSS
CVE-2018-7273
Media 5.5

In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables using printk calls within the function show_floppy in drivers/block/floppy.c. An attacker can read this information from dmesg and use the addr…

linux linux_kernel
0.02EPSS