imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2016-6758
Alta 7.8

An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to eleva…

linux linux_kernel
0.02EPSS
CVE-2014-2739
Media 4.6

The cma_req_handler function in drivers/infiniband/core/cma.c in the Linux kernel 3.14.x through 3.14.1 attempts to resolve an RDMA over Converged Ethernet (aka RoCE) address that is properly resolved within a different module, which allows remote attackers to…

linux linux_kernel
0.02EPSS
CVE-2021-26708
Alta 7.0

A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were implicitly introduced in the commits that …

linux linux_kernel · netapp aff_baseboard_management_controller · netapp baseboard_management_controller_500f_firmware · netapp baseboard_management_controller_a250_firmware · e altri 5
0.02EPSS
CVE-2016-8465
Alta 7.0

An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged proc…

linux linux_kernel
0.02EPSS
CVE-2016-8437
Critica 9.8

Improper input validation in Access Control APIs. Access control API may return memory range checking incorrectly. Product: Android. Versions: Kernel 3.18. Android ID: A-31623057. References: QC-CR#1009695.

linux linux_kernel
0.02EPSS
CVE-2016-8398
Critica 9.8

Unauthenticated messages processed by the UE. Certain NAS messages are processed when no EPS security context exists in the UE. Product: Android. Versions: Kernel 3.18. Android ID: A-31548486. References: QC-CR#877705.

linux linux_kernel
0.02EPSS
CVE-2004-0186
Alta 7.2

smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.

linux linux_kernel · samba samba
0.02EPSS
CVE-2015-3214
Media 6.9

The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.…

arista eos · debian debian_linux · lenovo emc_px12-400r_ivx · lenovo emc_px12-450r_ivx · e altri 15
0.02EPSS
CVE-2017-6264
Alta 7.8

An elevation of privilege vulnerability exists in the NVIDIA GPU driver (gm20b_clk_throt_set_cdev_state), where an out of bound memory read is used as a function pointer could lead to code execution in the kernel.This issue is rated as high because it could al…

linux linux_kernel
0.02EPSS
CVE-2021-4157
Alta 8.0

An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system …

fedoraproject fedora · linux linux_kernel · netapp h300e_firmware · netapp h300s_firmware · e altri 6
0.02EPSS
CVE-2003-0127
Alta 7.2

The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.

linux linux_kernel
0.02EPSS
CVE-2022-1199
Alta 7.5

A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability.

linux linux_kernel · netapp active_iq_unified_manager · netapp h300s_firmware · netapp h410c_firmware · e altri 4
0.02EPSS
CVE-2017-0458
Alta 7.0

An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process…

linux linux_kernel
0.02EPSS
CVE-2016-9793
Alta 7.8

The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified oth…

linux linux_kernel
0.02EPSS
CVE-2017-0613
Alta 7.0

An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first require…

linux linux_kernel
0.02EPSS
CVE-2021-42008
Alta 7.8

The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access.

debian debian_linux · linux linux_kernel · netapp h300e_firmware · netapp h300s_firmware · e altri 7
0.02EPSS
CVE-2013-0268
Media 6.2

The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended capability restrictions by executing a crafted application as root, as demonstrated by msr32.c.

linux linux_kernel
0.02EPSS
CVE-1999-0183
Media 6.4

Linux implementations of TFTP would allow access to files outside the restricted directory.

linux linux_kernel · tftp tftp
0.02EPSS
CVE-2016-8405
Media 4.7

An information disclosure vulnerability in kernel components including the ION subsystem, Binder, USB driver and networking subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate be…

linux linux_kernel
0.02EPSS
CVE-1999-0656
Media 5.0

The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.

linux linux_kernel
0.02EPSS
CVE-2023-6536
Media 6.5

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel…

debian debian_linux · linux linux_kernel · redhat codeready_linux_builder_eus · redhat codeready_linux_builder_eus_for_power_little_endian_eus · e altri 13
0.02EPSS
CVE-2023-6535
Media 6.5

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel…

linux linux_kernel · redhat codeready_linux_builder_eus · redhat codeready_linux_builder_eus_for_power_little_endian_eus · redhat codeready_linux_builder_for_arm64_eus · e altri 12
0.02EPSS
CVE-2017-0524
Alta 7.0

An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged p…

linux linux_kernel
0.02EPSS
CVE-2017-0519
Alta 7.0

An elevation of privilege vulnerability in the Qualcomm fingerprint sensor driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privil…

linux linux_kernel
0.02EPSS
CVE-2017-0456
Alta 7.0

An elevation of privilege vulnerability in the Qualcomm IPA driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. P…

linux linux_kernel
0.02EPSS