imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-1999-1225
Media 5.0

rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not…

digital ultrix · linux linux_kernel · netbsd netbsd · openbsd openbsd · e altri 1
0.02EPSS
CVE-2017-0307
Alta 7.8

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromis…

linux linux_kernel
0.02EPSS
CVE-2017-0518
Alta 7.0

An elevation of privilege vulnerability in the Qualcomm fingerprint sensor driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privil…

linux linux_kernel
0.02EPSS
CVE-2017-0516
Alta 7.0

An elevation of privilege vulnerability in the Qualcomm input hardware driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged…

linux linux_kernel
0.02EPSS
CVE-2021-31440
Alta 7.0

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specif…

linux linux_kernel · netapp cloud_backup · netapp h300e_firmware · netapp h300s_firmware · e altri 6
0.02EPSS
CVE-2015-0570
Alta 7.8

Stack-based buffer overflow in the SET_WPS_IE IOCTL implementation in wlan_hdd_hostapd.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, all…

linux linux_kernel
0.02EPSS
CVE-2021-4203
Media 6.8

A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal ker…

linux linux_kernel · netapp a700s_firmware · netapp active_iq_unified_manager · netapp bootstrap_os · e altri 12
0.02EPSS
CVE-2017-0306
Alta 7.8

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromis…

linux linux_kernel
0.02EPSS
CVE-2007-4774
Media 5.9

The Linux kernel before 2.4.36-rc1 has a race condition. It was possible to bypass systrace policies by flooding the ptraced process with SIGCONT signals, which can can wake up a PTRACED process.

linux linux_kernel
0.02EPSS
CVE-2016-7915
Media 5.5

The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) by connecting a device, as demonstr…

linux linux_kernel
0.02EPSS
CVE-2021-3752
Alta 7.1

A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest t…

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp h300e_firmware · e altri 15
0.02EPSS
CVE-2016-9120
Alta 7.8

Race condition in the ion_ioctl function in drivers/staging/android/ion/ion.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) by calling ION_IOC_FREE on two CPUs at the same time.

linux linux_kernel
0.02EPSS
CVE-2016-5344
Critica 9.8

Multiple integer overflows in the MDSS driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to cause a denial of service or possibly have unspecified other impac…

google android · linux linux_kernel
0.02EPSS
CVE-2019-15666
Media 4.4

An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial of service, because verify_newpolicy_info in net/xfrm/xfrm_user.c mishandles directory validation.

debian debian_linux · linux linux_kernel · opensuse leap
0.02EPSS
CVE-2007-4311
Media 6.8

The xfer_secondary_pool function in drivers/char/random.c in the Linux kernel 2.4 before 2.4.35 performs reseed operations on only the first few bytes of a buffer, which might make it easier for attackers to predict the output of the random number generator, r…

linux linux_kernel
0.02EPSS
CVE-2016-8459
Critica 9.8

Possible buffer overflow in storage subsystem. Bad parameters as part of listener responses to RPMB commands could lead to buffer overflow. Product: Android. Versions: Kernel 3.18. Android ID: A-32577972. References: QC-CR#988462.

linux linux_kernel
0.02EPSS
CVE-2016-8439
Critica 9.8

Possible buffer overflow in trust zone access control API. Buffer overflow may occur due to lack of buffer size checking. Product: Android. Versions: Kernel 3.18. Android ID: A-31625204. References: QC-CR#1027804.

linux linux_kernel
0.02EPSS
CVE-2018-13093
Media 5.5

An issue was discovered in fs/xfs/xfs_icache.c in the Linux kernel through 4.17.3. There is a NULL pointer dereference and panic in lookup_slow() on a NULL inode->i_ops pointer when doing pathwalks on a corrupted xfs image. This occurs because of a lack of pro…

linux linux_kernel
0.02EPSS
CVE-2018-11508
Media 5.5

The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.

canonical ubuntu_linux · linux linux_kernel
0.02EPSS
CVE-2021-41073
Alta 7.8

loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc/<pid>/maps for exploitation.

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp cloud_backup · e altri 9
0.02EPSS
CVE-2017-0338
Alta 7.8

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromis…

linux linux_kernel
0.02EPSS
CVE-2016-8430
Alta 7.8

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromis…

linux linux_kernel
0.02EPSS
CVE-2016-4486
Bassa 3.3

The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.

canonical ubuntu_linux · linux linux_kernel · novell suse_linux_enterprise_debuginfo · novell suse_linux_enterprise_desktop · e altri 6
0.02EPSS
CVE-2016-10283
Alta 7.0

An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process.…

linux linux_kernel
0.02EPSS
CVE-2017-0337
Alta 7.8

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromis…

linux linux_kernel
0.02EPSS