58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
Vulnerabilità Linux
15.026 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2018-17182 | HIGH 7.8 | canonical ubuntu_linux An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) via certain thread creation, map, unmap, | 3,2% | — |
| CVE-2005-2098 | MED 5.0 | linux linux_kernel The KEYCTL_JOIN_SESSION_KEYRING operation in the Linux kernel before 2.6.12.5 contains an error path that does not properly release the session management semaphore, which allows local users or remote attackers to cause a denial of service (semaphore hang) via | 3,2% | — |
| CVE-2022-2663 | MED 5.3 | debian debian_linux An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall may be able to be bypassed when users are using unencrypted IRC with nf_conntrack_irc configured. | 3,2% | — |
| CVE-2011-3359 | HIGH 7.5 | linux linux_kernel The dma_rx function in drivers/net/wireless/b43/dma.c in the Linux kernel before 2.6.39 does not properly allocate receive buffers, which allows remote attackers to cause a denial of service (system crash) via a crafted frame. | 3,2% | — |
| CVE-2021-38202 | HIGH 7.5 | linux linux_kernel fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd. | 3,2% | — |
| CVE-2009-1360 | HIGH 7.1 | linux linux_kernel The __inet6_check_established function in net/ipv6/inet6_hashtables.c in the Linux kernel before 2.6.29, when Network Namespace Support (aka NET_NS) is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) vi | 3,2% | — |
| CVE-2011-4326 | HIGH 7.1 | avaya 96x1_ip_deskphone_firmware The udp6_ufo_fragment function in net/ipv6/udp.c in the Linux kernel before 2.6.39, when a certain UDP Fragmentation Offload (UFO) configuration is enabled, allows remote attackers to cause a denial of service (system crash) by sending fragmented IPv6 UDP pack | 3,2% | — |
| CVE-2009-1265 | MED 5.0 | linux linux_kernel Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 2.6.24.4, and other versions before 2.6.30-rc1, might allow remote attackers to obtain sensitive information via a large length value, which causes "garbage" memory to be sent. | 3,2% | — |
| CVE-2019-19076 | MED 5.9 | canonical ubuntu_linux A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/cls.c in the Linux kernel before 5.3.6 allows attackers to cause a denial of service (memory consumption), aka CID-78beef629fd9. NOTE: This has been argued as n | 3,2% | — |
| CVE-2023-38428 | CRIT 9.1 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer, leading to an out-of-bounds read. | 3,2% | — |
| CVE-2006-3085 | HIGH 7.8 | linux linux_kernel xt_sctp in netfilter for Linux kernel before 2.6.17.1 allows attackers to cause a denial of service (infinite loop) via an SCTP chunk with a 0 length. | 3,1% | — |
| CVE-2020-25672 | HIGH 7.5 | debian debian_linux A memory leak vulnerability was found in Linux kernel in llcp_sock_connect | 3,1% | — |
| CVE-2009-4031 | HIGH 7.8 | linux linux_kernel The do_insn_fetch function in arch/x86/kvm/emulate.c in the x86 emulator in the KVM subsystem in the Linux kernel before 2.6.32-rc8-next-20091125 tries to interpret instructions that contain too many bytes to be valid, which allows guest OS users to cause a de | 3,1% | — |
| CVE-2005-3272 | MED 5.0 | linux linux_kernel Linux kernel before 2.6.12 allows remote attackers to poison the bridge forwarding table using frames that have already been dropped by filtering, which can cause the bridge to forward spoofed packets. | 3,1% | — |
| CVE-2015-8746 | HIGH 7.5 | linux linux_kernel fs/nfs/nfs4proc.c in the NFS client in the Linux kernel before 4.2.2 does not properly initialize memory for migration recovery operations, which allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) via crafted network tr | 3,1% | — |
| CVE-2001-0851 | MED 5.0 | caldera openlinux Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie. | 3,1% | — |
| CVE-2020-10711 | MED 5.9 | canonical ubuntu_linux A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_ | 3,1% | — |
| CVE-2016-10764 | CRIT 9.8 | linux linux_kernel In the Linux kernel before 4.9.6, there is an off by one in the drivers/mtd/spi-nor/cadence-quadspi.c cqspi_setup_flash() function. There are CQSPI_MAX_CHIPSELECT elements in the ->f_pdata array so the ">" should be ">=" instead. | 3,1% | — |
| CVE-2009-4026 | HIGH 7.8 | linux linux_kernel The mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (panic) via a crafted Delete Block ACK (aka DELBA) packet, related to an erroneous "code shuffling patch." | 3,1% | — |
| CVE-2023-38426 | CRIT 9.1 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is larger than the tag length. | 3,0% | — |
| CVE-2009-1633 | HIGH 7.1 | canonical ubuntu_linux Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode str | 3,0% | — |
| CVE-2015-2922 | LOW 3.3 | debian debian_linux The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Route | 3,0% | — |
| CVE-2019-17666 | HIGH 8.8 | canonical ubuntu_linux rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow. | 3,0% | — |
| CVE-2007-1497 | MED 5.0 | linux linux_kernel nf_conntrack in netfilter in the Linux kernel before 2.6.20.3 does not set nfctinfo during reassembly of fragmented packets, which leaves the default value as IP_CT_ESTABLISHED and might allow remote attackers to bypass certain rulesets using IPv6 fragments. | 3,0% | — |
| CVE-2008-5025 | HIGH 7.8 | linux linux_kernel Stack-based buffer overflow in the hfs_cat_find_brec function in fs/hfs/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfs filesystem image with an invalid catalog namele | 3,0% | — |