imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2023-1829
Alta 7.8

A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting …

linux linux_kernel
0.01EPSS
CVE-2016-8478
Media 4.7

An information disclosure vulnerability in the Qualcomm video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produc…

linux linux_kernel
0.01EPSS
CVE-2016-8416
Media 4.7

An information disclosure vulnerability in the Qualcomm video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produc…

linux linux_kernel
0.01EPSS
CVE-2009-3002
Media 4.9

The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_APPLETALK socket, related to the atalk_ge…

canonical ubuntu_linux · linux linux_kernel
0.01EPSS
CVE-2021-47384
Media 5.3

In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field If driver read tmp value sufficient for (tmp & 0x08) && (!(tmp & 0x80)) && ((tmp & 0x7) == ((tmp >> 4) & …

linux linux_kernel
0.01EPSS
CVE-1999-1166
Alta 7.2

Linux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by accessing and modifying kernel memory.

linux linux_kernel
0.01EPSS
CVE-2020-25668
Alta 7.0

A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.

debian debian_linux · linux linux_kernel · netapp 500f_firmware · netapp a250_firmware · e altri 11
0.01EPSS
CVE-2007-1861
Media 4.9

The nl_fib_lookup function in net/ipv4/fib_frontend.c in Linux Kernel before 2.6.20.8 allows attackers to cause a denial of service (kernel panic) via NETLINK_FIB_LOOKUP replies, which trigger infinite recursion and a stack overflow.

linux linux_kernel
0.01EPSS
CVE-2017-2636
Alta 7.0

Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2021-47241
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: ethtool: strset: fix message length calculation Outer nest for ETHTOOL_A_STRSET_STRINGSETS is not accounted for. This may result in ETHTOOL_MSG_STRSET_GET producing a warning like: calc…

linux linux_kernel
0.01EPSS
CVE-2023-52434
Alta 8.1

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOBs in smb2_parse_contexts() Validate offsets and lengths before dereferencing create contexts in smb2_parse_contexts(). This fixes following oops when accessing…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2016-10292
Media 5.5

A denial of service vulnerability in the Qualcomm Wi-Fi driver could enable a proximate attacker to cause a denial of service in the Wi-Fi subsystem. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: Ke…

linux linux_kernel
0.01EPSS
CVE-2012-3375
Media 4.9

The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via a crafted …

linux linux_kernel
0.01EPSS
CVE-2009-3001
Media 4.9

The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain data structure, which allows local users to read the contents of some kernel memory locations by calling getsockname on an AF_LLC socket.

canonical ubuntu_linux · linux linux_kernel
0.01EPSS
CVE-2024-35857
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: icmp: prevent possible NULL dereferences from icmp_build_probe() First problem is a double call to __in_dev_get_rcu(), because the second one could return NULL. if (__in_dev_get_rcu(dev) &&…

linux linux_kernel
0.01EPSS
CVE-1999-0400
Media 4.6

Denial of service in Linux 2.2.0 running the ldd command on a core file.

linux linux_kernel
0.01EPSS
CVE-2023-52798
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix dfs radar event locking The ath11k active pdevs are protected by RCU but the DFS radar event handling code calling ath11k_mac_get_ar_by_pdev_id() was not marked as a read-s…

linux linux_kernel
0.01EPSS
CVE-2013-2852
Media 6.9

Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format strin…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2017-0626
Media 5.5

An information disclosure vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without expli…

linux linux_kernel
0.01EPSS
CVE-2017-0624
Media 5.5

An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user…

linux linux_kernel
0.01EPSS
CVE-2014-9870
Alta 7.8

The Linux kernel before 3.11 on ARM platforms, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly consider user-space access to the TPIDRURW register, which allows local users to gain privileges via a crafted application, a…

google android · linux linux_kernel
0.01EPSS
CVE-2023-0394
Media 5.5

A NULL pointer dereference flaw was found in rawv6_push_pending_frames in net/ipv6/raw.c in the network subcomponent in the Linux kernel. This flaw causes the system to crash.

linux linux_kernel
0.01EPSS
CVE-2006-1863
Bassa 2.1

Directory traversal vulnerability in CIFS in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to CVE-2006-1864.

linux linux_kernel
0.01EPSS
CVE-2014-2568
Bassa 2.9

Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation. …

canonical ubuntu_linux · linux linux_kernel
0.01EPSS
CVE-2022-3910
Alta 7.8

Use After Free vulnerability in Linux Kernel allows Privilege Escalation. An improper Update of Reference Count in io_uring leads to Use-After-Free and Local Privilege Escalation. When io_msg_ring was invoked with a fixed file, it called io_fput_file() which i…

linux linux_kernel
0.01EPSS