imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2017-0630
Media 4.7

An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produ…

linux linux_kernel
0.01EPSS
CVE-2005-3810
Alta 7.8

ip_conntrack_proto_icmp.c in ctnetlink in Linux kernel 2.6.14 up to 2.6.14.3 allows attackers to cause a denial of service (kernel oops) via a message without ICMP ID (ICMP_ID) information, which leads to a null dereference.

linux linux_kernel
0.01EPSS
CVE-2016-8453
Alta 7.0

An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process.…

linux linux_kernel
0.01EPSS
CVE-2016-8444
Alta 7.0

An elevation of privilege vulnerability in the Qualcomm camera could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Produ…

linux linux_kernel
0.01EPSS
CVE-2016-8393
Alta 7.0

An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged p…

linux linux_kernel
0.01EPSS
CVE-2005-3753
Alta 7.8

Linux kernel before after 2.6.12 and before 2.6.13.1 might allow attackers to cause a denial of service (Oops) via certain IPSec packets that cause alignment problems in standard multi-block cipher processors. NOTE: it is not clear whether this issue can be t…

linux linux_kernel
0.01EPSS
CVE-2017-0623
Alta 7.0

An elevation of privilege vulnerability in the HTC bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader. This issue is rated as High because it first requires compromising a privileged process. Pr…

linux linux_kernel
0.01EPSS
CVE-2017-0622
Alta 7.0

An elevation of privilege vulnerability in the Goodix touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged proc…

linux linux_kernel
0.01EPSS
CVE-2013-0871
Media 6.9

Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allows local users to gain privileges via a PTRACE_SETREGS ptrace system call in a crafted application, as demonstrated by ptrace_death.

linux linux_kernel
0.01EPSS
CVE-2022-2602
Media 5.3

io_uring UAF, Unix SCM garbage collection

canonical ubuntu_linux · linux linux_kernel
0.01EPSS
CVE-2015-8963
Alta 7.0

Race condition in kernel/events/core.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect handling of an swevent data structure during a CPU unplug operation.

linux linux_kernel
0.01EPSS
CVE-2016-2065
Alta 7.8

sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service (out-of…

linux linux_kernel
0.01EPSS
CVE-2016-10288
Alta 7.0

An elevation of privilege vulnerability in the Qualcomm LED driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. P…

linux linux_kernel
0.01EPSS
CVE-1999-0257
Media 5.0

Nestea variation of teardrop IP fragmentation denial of service.

linux linux_kernel
0.01EPSS
CVE-2024-35960
Critica 9.1

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Properly link new fs rules into the tree Previously, add_rule_fg would only add newly created rules from the handle into the tree when they had a refcount of 1. On the other hand, …

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2007-2876
Media 6.1

The sctp_new function in (1) ip_conntrack_proto_sctp.c and (2) nf_conntrack_proto_sctp.c in Netfilter in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, allows remote attackers to cause a denial of service by causing certain invalid states tha…

linux linux_kernel
0.01EPSS
CVE-2022-47940
Alta 8.1

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5.18.18. fs/ksmbd/smb2pdu.c lacks length validation in the non-padding case in smb2_write.

linux linux_kernel
0.01EPSS
CVE-2016-1583
Alta 7.8

The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading …

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · novell suse_linux_enterprise_debuginfo · e altri 6
0.01EPSS
CVE-2016-6780
Alta 7.0

An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process…

linux linux_kernel
0.01EPSS
CVE-2016-6779
Alta 7.0

An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process…

linux linux_kernel
0.01EPSS
CVE-2016-6778
Alta 7.0

An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process…

linux linux_kernel
0.01EPSS
CVE-2018-1000028
Alta 7.4

Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS server (nfsd) that can result in remote users reading or writing files they should not be able to via NFS. This atta…

linux linux_kernel
0.01EPSS
CVE-2016-2066
Alta 7.8

Integer signedness error in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (memory cor…

linux linux_kernel
0.01EPSS
CVE-2023-39180
Media 4.0

A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of …

linux linux_kernel
0.01EPSS
CVE-2023-1998
Media 5.6

The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which disables the speculation feature as well as by using seccomp. We had noticed that on VMs of at least one major cloud provider, the kernel stil…

debian debian_linux · linux linux_kernel
0.01EPSS