imPC@ndo EN

Vulnerabilità Linux

14.774 CVE

CVE-2006-6106
Alta 7.5

Multiple buffer overflows in the cmtp_recv_interopmsg function in the Bluetooth driver (net/bluetooth/cmtp/capi.c) in the Linux kernel 2.4.22 up to 2.4.33.4 and 2.6.2 before 2.6.18.6, and 2.6.19.x, allow remote attackers to cause a denial of service (crash) an…

linux linux_kernel
0.06EPSS
CVE-1999-0804
Media 5.0

Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.

debian debian_linux · linux linux_kernel · redhat linux · suse suse_linux
0.06EPSS
CVE-2010-3432
Alta 7.8

The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs extraneous initializations of packet data structures, which allows remote attackers to cause a denial of service (panic) via a certain sequence of SCTP traffic.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse · e altri 1
0.06EPSS
CVE-2022-27666
Alta 7.8

A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp h300e_firmware · e altri 9
0.06EPSS
CVE-2016-5244
Alta 7.5

The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by reading an RDS message.

fedoraproject fedora · linux linux_kernel · redhat enterprise_linux · suse linux_enterprise_debuginfo · e altri 7
0.06EPSS
CVE-2022-34918
Alta 7.8

An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obta…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp h300s_firmware · e altri 4
0.05EPSS
CVE-2014-8160
Media 5.0

net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended acc…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse · e altri 11
0.05EPSS
CVE-2019-12818
Alta 7.5

An issue was discovered in the Linux kernel before 4.20.15. The nfc_llcp_build_tlv function in net/nfc/llcp_commands.c may return NULL. If the caller does not check for this, it will trigger a NULL pointer dereference. This will cause denial of service. This a…

linux linux_kernel
0.05EPSS
CVE-2009-1389
Alta 7.8

Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169.c) in the Linux kernel before 2.6.30 allows remote attackers to cause a denial of service (kernel memory corruption and crash) via a long packet.

linux kernel · linux linux_kernel
0.05EPSS
CVE-2014-4608
Alta 7.3

Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Liter…

canonical ubuntu_linux · linux linux_kernel · opensuse opensuse · suse linux_enterprise_real_time_extension · e altri 1
0.05EPSS
CVE-2019-19052
Alta 7.5

A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.

broadcom brocade_fabric_operating_system_firmware · canonical ubuntu_linux · debian debian_linux · linux linux_kernel · e altri 15
0.05EPSS
CVE-2014-9428
Alta 7.8

The batadv_frag_merge_packets function in net/batman-adv/fragmentation.c in the B.A.T.M.A.N. implementation in the Linux kernel through 3.18.1 uses an incorrect length field during a calculation of an amount of memory, which allows remote attackers to cause a …

linux linux_kernel
0.05EPSS
CVE-2005-3848
Alta 7.8

Memory leak in the icmp_push_reply function in Linux 2.6 before 2.6.12.6 and 2.6.13 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted packets that cause the ip_append_data function to fail, aka "DST leak in…

linux linux_kernel
0.05EPSS
CVE-2018-12714
Critica 9.8

An issue was discovered in the Linux kernel through 4.17.2. The filter parsing in kernel/trace/trace_events_filter.c could be called with no filter, which is an N=0 case when it expected at least one line to have been read, thus making the N-1 index invalid. T…

linux linux_kernel
0.05EPSS
CVE-2021-3773
Critica 9.8

A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks.

fedoraproject fedora · linux linux_kernel · oracle communications_cloud_native_core_binding_support_function · oracle communications_cloud_native_core_network_exposure_function · e altri 2
0.05EPSS
CVE-2020-16166
Bassa 3.7

The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · e altri 11
0.05EPSS
CVE-2008-5134
Alta 10.0

Buffer overflow in the lbs_process_bss function in drivers/net/wireless/libertas/scan.c in the libertas subsystem in the Linux kernel before 2.6.27.5 allows remote attackers to have an unknown impact via an "invalid beacon/probe response."

linux linux_kernel
0.05EPSS
CVE-2019-10125
Critica 9.8

An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aio_poll_wake() if an expected event is triggered immediately (e.g., by the close of a pair of pipes) after the return of vfs_poll(), and this will c…

linux linux_kernel · netapp active_iq_unified_manager · netapp cn1610_firmware · netapp hci_management_node · e altri 2
0.05EPSS
CVE-2014-6417
Alta 7.8

net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly consider the possibility of kmalloc failure, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via a long …

linux linux_kernel
0.05EPSS
CVE-2017-12762
Critica 9.8

In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local buffer of constant size using strcpy without a length check which can cause a buffer overflow. This affects the Linux kernel 4.9-stable tree, 4.12-stable tree, 3.18-stable tree, a…

canonical ubuntu_linux · linux linux_kernel
0.05EPSS
CVE-2014-7841
Media 5.0

The sctp_process_param function in net/sctp/sm_make_chunk.c in the SCTP implementation in the Linux kernel before 3.17.4, when ASCONF is used, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via a malformed INIT…

linux linux_kernel
0.05EPSS
CVE-2009-4536
Alta 7.8

drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel 2.6.32.3 and earlier handles Ethernet frames that exceed the MTU by processing certain trailing payload data as if it were a complete frame, which allows remote attackers to bypass packet f…

debian debian_linux · linux linux_kernel
0.05EPSS
CVE-2006-2934
Media 5.0

SCTP conntrack (ip_conntrack_proto_sctp.c) in netfilter for Linux kernel 2.6.17 before 2.6.17.3 and 2.6.16 before 2.6.16.23 allows remote attackers to cause a denial of service (crash) via a packet without any chunks, which causes a variable to contain an inva…

linux linux_kernel
0.05EPSS
CVE-2019-15926
Critica 9.1

An issue was discovered in the Linux kernel before 5.2.3. Out of bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx and ath6kl_wmi_cac_event_rx in the file drivers/net/wireless/ath/ath6kl/wmi.c.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.05EPSS
CVE-2017-1000364
Alta 7.4

An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguar…

linux linux_kernel
0.05EPSS