imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2013-7267
Media 4.9

The atalk_recvmsg function in net/appletalk/ddp.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel mem…

linux linux_kernel
0.00EPSS
CVE-2013-7266
Media 4.9

The mISDN_sock_recvmsg function in drivers/isdn/mISDN/socket.c in the Linux kernel before 3.12.4 does not ensure that a certain length value is consistent with the size of an associated data structure, which allows local users to obtain sensitive information f…

linux linux_kernel
0.00EPSS
CVE-2013-7264
Media 4.9

The l2tp_ip_recvmsg function in net/l2tp/l2tp_ip.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel sta…

linux linux_kernel
0.00EPSS
CVE-2011-1090
Media 4.9

The __nfs4_proc_set_acl function in fs/nfs/nfs4proc.c in the Linux kernel before 2.6.38 stores NFSv4 ACL data in memory that is allocated by kmalloc but not properly freed, which allows local users to cause a denial of service (panic) via a crafted attempt to …

linux linux_kernel
0.00EPSS
CVE-2010-3084
Alta 7.2

Buffer overflow in the niu_get_ethtool_tcam_all function in drivers/net/niu.c in the Linux kernel before 2.6.36-rc4 allows local users to cause a denial of service or possibly have unspecified other impact via the ETHTOOL_GRXCLSRLALL ethtool command.

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2010-2492
Alta 7.8

Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors.

avaya aura_communication_manager · avaya aura_presence_services · avaya aura_session_manager · avaya aura_system_manager · e altri 5
0.00EPSS
CVE-2010-2226
Bassa 2.1

The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly check the file descriptors passed to the SWAPEXT ioctl, which allows local users to leverage write access and obtain read access by swapping one file into anothe…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · suse linux_enterprise_desktop · e altri 2
0.00EPSS
CVE-2006-4535
Media 4.9

The Linux kernel 2.6.17.10 and 2.6.17.11 and 2.6.18-rc5 allows local users to cause a denial of service (crash) via an SCTP socket with a certain SO_LINGER value, possibly related to the patch for CVE-2006-3745. NOTE: older kernel versions for specific Linux …

linux linux_kernel
0.00EPSS
CVE-2006-1860
Bassa 2.1

lease_init in fs/locks.c in Linux kernel before 2.6.16.16 allows attackers to cause a denial of service (fcntl_setlease lockup) via actions that cause lease_init to free a lock that might not have been allocated on the stack.

linux linux_kernel
0.00EPSS
CVE-2006-0095
Bassa 2.1

dm-crypt in Linux kernel 2.6.15 and earlier does not clear a structure before it is freed, which leads to a memory disclosure that could allow local users to obtain sensitive information about a cryptographic key.

linux linux_kernel
0.00EPSS
CVE-2026-46037
Alta 8.2

In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: validate reply type before using icmp_pointers Extended echo replies use ICMP_EXT_ECHOREPLY as the outbound reply type. That value is outside the range covered by icmp_pointers[]…

linux linux_kernel
0.00EPSS
CVE-2026-23457
Alta 8.6

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() sip_help_tcp() parses the SIP Content-Length header with simple_strtoul(), which returns unsigned long, but s…

linux linux_kernel
0.00EPSS
CVE-2024-57947
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map fill The initial buffer has to be inited to all-ones, but it must restrict it to the size of the first field, not the total field size. After each …

linux linux_kernel
0.00EPSS
CVE-2020-15393
Media 5.5

In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebeb8db770.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse leap
0.00EPSS
CVE-2019-19526
Media 4.6

In the Linux kernel before 5.3.9, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/nfc/pn533/usb.c driver, aka CID-6af3aa57a098.

canonical ubuntu_linux · linux linux_kernel · opensuse leap
0.00EPSS
CVE-2018-19854
Media 4.7

An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memo…

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2010-5328
Media 5.5

include/linux/init_task.h in the Linux kernel before 2.6.35 does not prevent signals with a process group ID of zero from reaching the swapper process, which allows local users to cause a denial of service (system crash) by leveraging access to this process gr…

linux linux_kernel
0.00EPSS
CVE-2010-0291
Media 4.6

The Linux kernel before 2.6.32.4 allows local users to gain privileges or cause a denial of service (panic) by calling the (1) mmap or (2) mremap function, aka the "do_mremap() mess" or "mremap/mmap mess."

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2005-3783
Media 4.9

The ptrace functionality (ptrace.c) in Linux kernel 2.6 before 2.6.14.2, using CLONE_THREAD, does not use the thread group ID to check whether it is attaching to itself, which allows local users to cause a denial of service (crash).

linux linux_kernel
0.00EPSS
CVE-2026-64208
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks Change the krb5 crypto library to provide facilities to precheck the length of the message about to be decrypted or verif…

linux linux_kernel
0.00EPSS
CVE-2024-46696
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix potential UAF in nfsd4_cb_getattr_release Once we drop the delegation reference, the fields embedded in it are no longer safe to access. Do that last.

linux linux_kernel
0.00EPSS
CVE-2022-26490
Alta 7.8

st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp h300e_firmware · e altri 7
0.00EPSS
CVE-2006-5331
Media 5.5

The altivec_unavailable_exception function in arch/powerpc/kernel/traps.c in the Linux kernel before 2.6.19 on 64-bit systems mishandles the case where CONFIG_ALTIVEC is defined and the CPU actually supports Altivec, but the Altivec support was not detected by…

linux linux_kernel
0.00EPSS
CVE-2017-5549
Media 5.5

The klsi_105_get_line_state function in drivers/usb/serial/kl5kusb105.c in the Linux kernel before 4.9.5 places uninitialized heap-memory contents into a log entry upon a failure to read the line status, which allows local users to obtain sensitive information…

linux linux_kernel
0.00EPSS
CVE-2010-3296
Bassa 2.1

The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse · e altri 3
0.00EPSS