imPC@ndo IT

Linux vulnerabilities

14.775 CVE

CVE-2016-8395
Medium 4.7

A denial of service vulnerability in the NVIDIA camera driver could enable an attacker to cause a local permanent denial of service, which may require reflashing the operating system to repair the device. This issue is rated as High due to the possibility of l…

linux linux_kernel
0.01EPSS
CVE-2022-41218
Medium 5.5

In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release.

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2011-1082
Medium 4.9

fs/eventpoll.c in the Linux kernel before 2.6.38 places epoll file descriptors within other epoll data structures without properly checking for (1) closed loops or (2) deep chains, which allows local users to cause a denial of service (deadlock or stack memory…

linux linux_kernel
0.01EPSS
CVE-2021-47245
High 8.2

In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: Fix out of bounds when parsing TCP options The TCP option parser in synproxy (synproxy_parse_options) could read one byte out of bounds. When the length is 1, the execut…

linux linux_kernel
0.01EPSS
CVE-2022-48666
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix a use-after-free There are two .exit_cmd_priv implementations. Both implementations use resources associated with the SCSI host. Make sure that these resources are still avai…

linux linux_kernel
0.01EPSS
CVE-2001-0316
Medium 4.6

Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call.

linux linux_kernel
0.01EPSS
CVE-2014-0049
High 7.4

Buffer overflow in the complete_emulated_mmio function in arch/x86/kvm/x86.c in the Linux kernel before 3.13.6 allows guest OS users to execute arbitrary code on the host OS by leveraging a loop that triggers an invalid memory copy affecting certain cancel_wor…

linux linux_kernel
0.01EPSS
CVE-2011-4131
Medium 4.6

The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.

linux linux_kernel
0.01EPSS
CVE-2019-5489
Medium 5.5

The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allowing sniffing of secret information. (Fixing this affects the …

linux linux_kernel · netapp active_iq_performance_analytics_services · netapp element_software_management_node
0.01EPSS
CVE-2018-10876
Medium 5.0

A flaw was found in Linux kernel in the ext4 filesystem code. A use-after-free is possible in ext4_ext_remove_space() function when mounting and operating a crafted ext4 image.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2024-41007
High 7.5

In the Linux kernel, the following vulnerability has been resolved: tcp: avoid too many retransmit packets If a TCP socket is using TCP_USER_TIMEOUT, and the other peer retracted its window to zero, tcp_retransmit_timer() can retransmit a packet every two ji…

linux linux_kernel
0.01EPSS
CVE-2023-28866
Medium 5.3

In the Linux kernel through 6.2.8, net/bluetooth/hci_sync.c allows out-of-bounds access because amp_init1[] and amp_init2[] are supposed to have an intentionally invalid element, but do not.

linux linux_kernel
0.01EPSS
CVE-2022-29582
High 7.0

In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequ…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2018-1087
High 8.0

kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS …

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · redhat enterprise_linux · and 7 more
0.01EPSS
CVE-2017-0435
High 7.0

An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process.…

google android · linux linux_kernel
0.01EPSS
CVE-2007-1730
Medium 6.6

Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later allows local users to read kernel memory or cause a denial of service (oops) via a negative optlen value.

linux linux_kernel
0.01EPSS
CVE-2024-27393
High 7.5

In the Linux kernel, the following vulnerability has been resolved: xen-netfront: Add missing skb_mark_for_recycle Notice that skb_mark_for_recycle() is introduced later than fixes tag in commit 6a5bcd84e886 ("page_pool: Allow drivers to hint on SKB recyclin…

linux linux_kernel
0.01EPSS
CVE-2005-3808
Medium 4.9

Integer overflow in the invalidate_inode_pages2_range function in mm/truncate.c in Linux kernel 2.6.11 to 2.6.14 allows local users to cause a denial of service (hang) via 64-bit mmap calls that are not properly handled on a 32-bit system.

linux linux_kernel
0.01EPSS
CVE-2004-0228
High 7.2

Integer signedness error in the cpufreq proc handler (cpufreq_procctl) in Linux kernel 2.6 allows local users to gain privileges.

linux linux_kernel
0.01EPSS
CVE-2016-8475
Medium 4.7

An information disclosure vulnerability in the HTC input driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: An…

linux linux_kernel
0.01EPSS
CVE-2016-8474
Medium 4.7

An information disclosure vulnerability in the STMicroelectronics driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Pr…

linux linux_kernel
0.01EPSS
CVE-2016-8473
Medium 4.7

An information disclosure vulnerability in the STMicroelectronics driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Pr…

linux linux_kernel
0.01EPSS
CVE-2016-8469
Medium 4.7

An information disclosure vulnerability in the camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Andro…

linux linux_kernel
0.01EPSS
CVE-2000-0227
Low 2.1

The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max parameter, which allows local users to cause a denial of service by requesting a large number of sockets.

linux linux_kernel
0.01EPSS
CVE-2021-47397
High 7.5

In the Linux kernel, the following vulnerability has been resolved: sctp: break out if skb_header_pointer returns NULL in sctp_rcv_ootb We should always check if skb_header_pointer's return is NULL before using it, otherwise it may cause null-ptr-deref, as s…

linux linux_kernel
0.01EPSS