imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2009-4307
Alta 7.1

The ext4_fill_flex_info function in fs/ext4/super.c in the Linux kernel before 2.6.32-git6 allows user-assisted remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ext4 filesystem containing a super block with a large…

linux linux_kernel
0.03EPSS
CVE-2006-1242
Media 5.0

The ip_push_pending_frames function in Linux 2.4.x and 2.6.x before 2.6.16 increments the IP ID field when sending a RST after receiving unsolicited TCP SYN-ACK packets, which allows remote attackers to conduct an Idle Scan (nmap -sI) attack, which bypasses in…

linux linux_kernel
0.03EPSS
CVE-2019-19069
Alta 7.5

A memory leak in the fastrpc_dma_buf_attach() function in drivers/misc/fastrpc.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering dma_get_sgtable() failures, aka CID-fc739a058d99.

broadcom fabric_operating_system · canonical ubuntu_linux · linux linux_kernel · netapp active_iq_unified_manager · e altri 12
0.03EPSS
CVE-2005-3623
Media 5.0

nfs2acl.c in the Linux kernel 2.6.14.4 does not check for MAY_SATTR privilege before setting access controls (ACL) on files on exported NFS filesystems, which allows remote attackers to bypass ACLs for readonly mounted NFS filesystems.

linux linux_kernel
0.03EPSS
CVE-2019-19377
Alta 7.8

In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and unmounting can lead to a use-after-free in btrfs_queue_work in fs/btrfs/async-thread.c.

linux linux_kernel · netapp active_iq_unified_manager · netapp cloud_backup · netapp solidfire_baseboard_management_controller · e altri 1
0.03EPSS
CVE-2005-3110
Bassa 2.6

Race condition in ebtables netfilter module (ebtables.c) in Linux 2.6, when running on an SMP system that is operating under a heavy load, might allow remote attackers to cause a denial of service (crash) via a series of packets that cause a value to be modifi…

linux linux_kernel
0.03EPSS
CVE-2011-1581
Alta 9.0

The bond_select_queue function in drivers/net/bonding/bond_main.c in the Linux kernel before 2.6.39, when a network device with a large number of receive queues is installed but the default tx_queues setting is used, does not properly restrict queue indexes, w…

linux linux_kernel
0.03EPSS
CVE-2006-2446
Media 5.4

Race condition between the kfree_skb and __skb_unlink functions in the socket buffer handling in Linux kernel 2.6.9, and possibly other versions, allows remote attackers to cause a denial of service (crash), as demonstrated using the TCP stress tests from the …

linux linux_kernel
0.03EPSS
CVE-2005-2801
Alta 7.5

xattr.c in the ext2 and ext3 file system code for Linux kernel 2.6 does not properly compare the name_index fields when sharing xattr blocks, which could prevent default ACLs from being applied.

linux linux_kernel
0.03EPSS
CVE-2021-38201
Alta 7.5

net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 READ_PLUS operations.

linux linux_kernel · netapp element_software · netapp hci_bootstrap_os · netapp hci_management_node · e altri 1
0.03EPSS
CVE-2011-1493
Alta 7.5

Array index error in the rose_parse_national function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by composing FAC_NATIONAL_DI…

linux linux_kernel
0.03EPSS
CVE-2009-2844
Alta 7.8

cfg80211 in net/wireless/scan.c in the Linux kernel 2.6.30-rc1 and other versions before 2.6.31-rc6 allows remote attackers to cause a denial of service (crash) via a sequence of beacon frames in which one frame omits an SSID Information Element (IE) and the s…

linux kernel · linux linux_kernel
0.03EPSS
CVE-2021-38207
Alta 7.5

drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attackers to cause a denial of service (buffer overflow and lockup) by sending heavy network traffic for about ten minutes.

linux linux_kernel
0.03EPSS
CVE-2005-3275
Bassa 2.6

The NAT code (1) ip_nat_proto_tcp.c and (2) ip_nat_proto_udp.c in Linux kernel 2.6 before 2.6.13 and 2.4 before 2.4.32-rc1 incorrectly declares a variable to be static, which allows remote attackers to cause a denial of service (memory corruption) by causing t…

linux linux_kernel
0.03EPSS
CVE-2012-6638
Alta 7.8

The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel before 3.2.24 allows remote attackers to cause a denial of service (kernel resource consumption) via a flood of SYN+FIN TCP packets, a different vulnerability than CVE-2012-2663.

linux linux_kernel
0.03EPSS
CVE-2017-18174
Critica 9.8

In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls the pinctrl_unregister function, leading to a double free.

linux linux_kernel
0.03EPSS
CVE-2016-2070
Alta 7.5

The tcp_cwnd_reduction function in net/ipv4/tcp_input.c in the Linux kernel before 4.3.5 allows remote attackers to cause a denial of service (divide-by-zero error and system crash) via crafted TCP traffic.

linux linux_kernel
0.03EPSS
CVE-2003-0961
Alta 7.2

Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges.

linux linux_kernel
0.03EPSS
CVE-2019-18812
Alta 7.5

A memory leak in the sof_dfsentry_write() function in sound/soc/sof/debug.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-c0a333d842ef.

linux linux_kernel
0.03EPSS
CVE-2010-1188
Alta 7.1

Use-after-free vulnerability in net/ipv4/tcp_input.c in the Linux kernel 2.6 before 2.6.20, when IPV6_RECVPKTINFO is set on a listening socket, allows remote attackers to cause a denial of service (kernel panic) via a SYN packet while the socket is in a listen…

linux linux_kernel
0.03EPSS
CVE-2016-5343
Critica 9.8

drivers/soc/qcom/qdsp6v2/voice_svc.c in the QDSP6v2 Voice Service driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service (memory corr…

linux linux_kernel
0.03EPSS
CVE-2014-4014
Media 6.2

The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated by setti…

linux linux_kernel
0.03EPSS
CVE-2019-19814
Alta 7.8

In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this.

linux linux_kernel
0.03EPSS
CVE-2008-4934
Alta 7.8

The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) v…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.03EPSS
CVE-2019-19816
Alta 7.8

In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volumes.c, because a value of 1 for the number of data stripes is mishandled.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp active_iq_unified_manager · e altri 9
0.03EPSS