imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2005-0449
Alta 7.1

The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are not properly handled by the skb_checksum_help function.

linux linux_kernel
0.05EPSS
CVE-2005-2459
Media 5.0

The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a certain compressed file that leads to a null pointer derefere…

debian debian_linux · linux linux_kernel
0.05EPSS
CVE-2009-0778
Alta 7.1

The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Hos…

linux linux_kernel · vmware esx · vmware server · vmware vcenter · e altri 2
0.05EPSS
CVE-2013-1059
Alta 7.8

net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an auth_reply message that triggers an attempted build_request …

canonical ubuntu_linux · linux linux_kernel
0.05EPSS
CVE-2010-0008
Alta 7.8

The sctp_rcv_ootb function in the SCTP implementation in the Linux kernel before 2.6.23 allows remote attackers to cause a denial of service (infinite loop) via (1) an Out Of The Blue (OOTB) chunk or (2) a chunk of zero length.

linux linux_kernel
0.05EPSS
CVE-2014-8709
Media 5.0

The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allows remote attackers to obtain sensitive cleartext information by reading packets.

linux linux_kernel
0.05EPSS
CVE-2020-13143
Media 6.5

gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp a700s_firmware · e altri 20
0.05EPSS
CVE-2019-11815
Alta 8.1

An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp active_iq_unified_manager · e altri 10
0.04EPSS
CVE-2019-19074
Alta 7.5

A memory leak in the ath9k_wmi_cmd() function in drivers/net/wireless/ath/ath9k/wmi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-728c1e2a05e4.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.04EPSS
CVE-2012-2744
Alta 7.8

net/ipv6/netfilter/nf_conntrack_reasm.c in the Linux kernel before 2.6.34, when the nf_conntrack_ipv6 module is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via certain types of fragmented IPv6 packe…

linux linux_kernel
0.04EPSS
CVE-2019-3900
Alta 7.7

An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, mayb…

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · e altri 10
0.04EPSS
CVE-2017-16914
Media 5.9

The "stub_send_ret_submit()" function (drivers/usb/usbip/stub_tx.c) in the Linux Kernel before version 4.14.8, 4.9.71, 4.1.49, and 4.4.107 allows attackers to cause a denial of service (NULL pointer dereference) via a specially crafted USB over IP packet.

linux linux_kernel
0.04EPSS
CVE-2006-2451
Media 4.6

The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of service (disk consumption) and possibly gain privileges via the PR_SET_DUMPABLE argument of the prctl functio…

linux linux_kernel
0.04EPSS
CVE-2011-1770
Alta 7.5

Integer underflow in the dccp_parse_options function (net/dccp/options.c) in the Linux kernel before 2.6.33.14 allows remote attackers to cause a denial of service via a Datagram Congestion Control Protocol (DCCP) packet with an invalid feature options length,…

fedoraproject fedora · linux linux_kernel
0.04EPSS
CVE-2014-2706
Alta 7.1

Race condition in the mac80211 subsystem in the Linux kernel before 3.13.7 allows remote attackers to cause a denial of service (system crash) via network traffic that improperly interacts with the WLAN_STA_PS_STA state (aka power-save mode), related to sta_in…

linux linux_kernel · oracle linux · suse linux_enterprise_high_availability_extension · suse suse_linux_enterprise_desktop · e altri 1
0.04EPSS
CVE-2008-3915
Alta 9.3

Buffer overflow in nfsd in the Linux kernel before 2.6.26.4, when NFSv4 is enabled, allows remote attackers to have an unknown impact via vectors related to decoding an NFSv4 acl.

linux linux_kernel
0.04EPSS
CVE-2019-15504
Critica 9.8

drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir).

canonical ubuntu_linux · linux linux_kernel
0.04EPSS
CVE-2012-2127
Media 5.0

fs/proc/root.c in the procfs implementation in the Linux kernel before 3.2 does not properly interact with CLONE_NEWPID clone system calls, which allows remote attackers to cause a denial of service (reference leak and memory consumption) by making many connec…

linux linux_kernel
0.04EPSS
CVE-2010-4164
Alta 7.8

Multiple integer underflows in the x25_parse_facilities function in net/x25/x25_facilities.c in the Linux kernel before 2.6.36.2 allow remote attackers to cause a denial of service (system crash) via malformed X.25 (1) X25_FAC_CLASS_A, (2) X25_FAC_CLASS_B, (3)…

debian debian_linux · linux linux_kernel · opensuse opensuse · suse linux_enterprise_desktop · e altri 3
0.04EPSS
CVE-2003-0244
Media 5.0

The route cache implementation in Linux 2.4, and the Netfilter IP conntrack module, allows remote attackers to cause a denial of service (CPU consumption) via packets with forged source addresses that cause a large number of hash table collisions.

linux linux_kernel
0.04EPSS
CVE-2009-1439
Alta 7.8

Buffer overflow in fs/cifs/connect.c in CIFS in the Linux kernel 2.6.29 and earlier allows remote attackers to cause a denial of service (crash) via a long nativeFileSystem field in a Tree Connect response to an SMB mount request.

linux linux_kernel
0.04EPSS
CVE-2006-4623
Alta 7.8

The Unidirectional Lightweight Encapsulation (ULE) decapsulation component in dvb-core/dvb_net.c in the dvb driver in the Linux kernel 2.6.17.8 allows remote attackers to cause a denial of service (crash) via an SNDU length of 0 in a ULE packet.

linux linux_kernel
0.04EPSS
CVE-2017-7618
Alta 7.5

crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling its own callback, and infinite recursion) by triggering EBUSY on a full queue.

linux linux_kernel
0.04EPSS
CVE-1999-0986
Media 5.0

The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.

debian debian_linux · linux linux_kernel · redhat linux
0.04EPSS
CVE-2017-1000410
Alta 7.5

The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack variables that may be returned to an att…

debian debian_linux · linux linux_kernel · redhat enterprise_linux_desktop · redhat enterprise_linux_server · e altri 5
0.04EPSS