imPC@ndo IT

Linux vulnerabilities

14.775 CVE

CVE-2018-5391
High 7.5

The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various …

canonical ubuntu_linux · debian debian_linux · f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · and 47 more
0.32EPSS
CVE-2008-4609
High 7.1

The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that m…

bsd bsd · bsdi bsd_os · cisco catalyst_blade_switch_3020_firmware · cisco catalyst_blade_switch_3120_firmware · and 15 more
0.32EPSS
CVE-1999-0524
Medium 4.0

ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.

apple mac_os_x · apple macos · cisco ios · hp hp-ux · and 10 more
0.32EPSS
CVE-2017-16995
High 7.8

The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging incorrect sign extension.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.30EPSS
CVE-2017-0561
Critical 9.8

A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. This issue is rated as Critical due to the possibility of remote code execution in the context of…

linux linux_kernel
0.30EPSS
CVE-2023-52442
Critical 9.1

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in compound request `smb2_get_msg()` in smb2_get_ksmbd_tcon() and smb2_check_user_session() will always return the first request smb2 header in a compo…

linux linux_kernel
0.30EPSS
CVE-2023-52755
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab out of bounds write in smb_inherit_dacl() slab out-of-bounds write is caused by that offsets is bigger than pntsd allocation size. This patch add the check to validate 3 offs…

linux linux_kernel
0.28EPSS
CVE-2021-3490
High 7.8

The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution. This issue was fi…

canonical ubuntu_linux · linux linux_kernel
0.27EPSS
CVE-2016-3955
Critical 9.8

The usbip_recv_xbuff function in drivers/usb/usbip/usbip_common.c in the Linux kernel before 4.5.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted length value in a USB/IP packe…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.26EPSS
CVE-2016-7117
Critical 9.8

Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.24EPSS
CVE-2017-5972
High 7.5

The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many TCP SYN packets, as demo…

linux linux_kernel
0.24EPSS
CVE-2015-8660
Medium 6.7

The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted…

linux linux_kernel
0.22EPSS
CVE-2023-52440
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob() If authblob->SessionKey.Length is bigger than session key size(CIFS_KEY_SIZE), slub overflow can happen in key exchange codes. ci…

linux linux_kernel
0.22EPSS
CVE-2022-43945
High 7.5

The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks the number of pages held by each NFSD thread by combining the receive and send buffers of a remote procedure call (RPC) into a single array …

linux linux_kernel · netapp active_iq_unified_manager · netapp h300s_firmware · netapp h410c_firmware · and 3 more
0.21EPSS
CVE-2010-1173
High 7.1

The sctp_process_unk_param function in net/sctp/sm_make_chunk.c in the Linux kernel 2.6.33.3 and earlier, when SCTP is enabled, allows remote attackers to cause a denial of service (system crash) via an SCTPChunkInit packet containing multiple invalid paramete…

linux linux_kernel
0.21EPSS
CVE-2004-1137
High 10.0

Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers to cause a denial of service or execute arbitrary code via (1) the ip_mc_source function, which decrements a counter to -…

linux linux_kernel · ubuntu ubuntu_linux
0.21EPSS
CVE-2017-1000112
High 7.0

Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE __ip_append_data() calls ip_ufo_append_data() to append. However in between two send() calls, the append path can be switched from UFO to no…

linux linux_kernel
0.21EPSS
CVE-2001-1244
Medium 5.0

Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less …

freebsd freebsd · hp hp-ux · hp vvos · linux linux_kernel · and 5 more
0.21EPSS
CVE-2006-2444
High 7.8

The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) via unspecified remote attack vectors that cause failures in snmp_trap_decode that trigger (1) frees of random m…

linux linux_kernel
0.21EPSS
CVE-2012-0207
High 7.5

The igmp_heard_query function in net/ipv4/igmp.c in the Linux kernel before 3.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and panic) via IGMP packets.

linux linux_kernel · redhat enterprise_linux_eus
0.20EPSS
CVE-2011-2189
High 7.5

net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via requests to a d…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · redhat enterprise_linux · and 1 more
0.18EPSS
CVE-2017-7308
High 7.8

The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain priv…

linux linux_kernel
0.18EPSS
CVE-2010-2943
High 8.1

The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an a…

avaya aura_communication_manager · avaya aura_presence_services · avaya aura_session_manager · avaya aura_system_manager · and 6 more
0.17EPSS
CVE-2019-14901
Critical 9.8

A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary code. The hi…

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel
0.17EPSS
CVE-2009-0065
High 10.0

Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.28-git8 allows remote attackers to have an unknown impact via an FWD-TSN (aka FORWARD-TSN) chunk with a large stream ID.…

linux linux_kernel
0.17EPSS