imPC@ndo IT

Linux vulnerabilities

14.775 CVE

CVE-2017-0630
Medium 4.7

An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produ…

linux linux_kernel
0.01EPSS
CVE-2005-3810
High 7.8

ip_conntrack_proto_icmp.c in ctnetlink in Linux kernel 2.6.14 up to 2.6.14.3 allows attackers to cause a denial of service (kernel oops) via a message without ICMP ID (ICMP_ID) information, which leads to a null dereference.

linux linux_kernel
0.01EPSS
CVE-2016-8453
High 7.0

An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process.…

linux linux_kernel
0.01EPSS
CVE-2016-8444
High 7.0

An elevation of privilege vulnerability in the Qualcomm camera could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Produ…

linux linux_kernel
0.01EPSS
CVE-2016-8393
High 7.0

An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged p…

linux linux_kernel
0.01EPSS
CVE-2005-3753
High 7.8

Linux kernel before after 2.6.12 and before 2.6.13.1 might allow attackers to cause a denial of service (Oops) via certain IPSec packets that cause alignment problems in standard multi-block cipher processors. NOTE: it is not clear whether this issue can be t…

linux linux_kernel
0.01EPSS
CVE-2017-0623
High 7.0

An elevation of privilege vulnerability in the HTC bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader. This issue is rated as High because it first requires compromising a privileged process. Pr…

linux linux_kernel
0.01EPSS
CVE-2017-0622
High 7.0

An elevation of privilege vulnerability in the Goodix touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged proc…

linux linux_kernel
0.01EPSS
CVE-2013-0871
Medium 6.9

Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allows local users to gain privileges via a PTRACE_SETREGS ptrace system call in a crafted application, as demonstrated by ptrace_death.

linux linux_kernel
0.01EPSS
CVE-2022-2602
Medium 5.3

io_uring UAF, Unix SCM garbage collection

canonical ubuntu_linux · linux linux_kernel
0.01EPSS
CVE-2015-8963
High 7.0

Race condition in kernel/events/core.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect handling of an swevent data structure during a CPU unplug operation.

linux linux_kernel
0.01EPSS
CVE-2016-2065
High 7.8

sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service (out-of…

linux linux_kernel
0.01EPSS
CVE-2016-10288
High 7.0

An elevation of privilege vulnerability in the Qualcomm LED driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. P…

linux linux_kernel
0.01EPSS
CVE-1999-0257
Medium 5.0

Nestea variation of teardrop IP fragmentation denial of service.

linux linux_kernel
0.01EPSS
CVE-2024-35960
Critical 9.1

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Properly link new fs rules into the tree Previously, add_rule_fg would only add newly created rules from the handle into the tree when they had a refcount of 1. On the other hand, …

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2007-2876
Medium 6.1

The sctp_new function in (1) ip_conntrack_proto_sctp.c and (2) nf_conntrack_proto_sctp.c in Netfilter in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, allows remote attackers to cause a denial of service by causing certain invalid states tha…

linux linux_kernel
0.01EPSS
CVE-2022-47940
High 8.1

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5.18.18. fs/ksmbd/smb2pdu.c lacks length validation in the non-padding case in smb2_write.

linux linux_kernel
0.01EPSS
CVE-2016-1583
High 7.8

The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading …

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · novell suse_linux_enterprise_debuginfo · and 6 more
0.01EPSS
CVE-2016-6780
High 7.0

An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process…

linux linux_kernel
0.01EPSS
CVE-2016-6779
High 7.0

An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process…

linux linux_kernel
0.01EPSS
CVE-2016-6778
High 7.0

An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process…

linux linux_kernel
0.01EPSS
CVE-2018-1000028
High 7.4

Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS server (nfsd) that can result in remote users reading or writing files they should not be able to via NFS. This atta…

linux linux_kernel
0.01EPSS
CVE-2016-2066
High 7.8

Integer signedness error in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (memory cor…

linux linux_kernel
0.01EPSS
CVE-2023-39180
Medium 4.0

A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of …

linux linux_kernel
0.01EPSS
CVE-2023-1998
Medium 5.6

The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which disables the speculation feature as well as by using seccomp. We had noticed that on VMs of at least one major cloud provider, the kernel stil…

debian debian_linux · linux linux_kernel
0.01EPSS