Vulnerability index

Browse CVEs

664 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Linux Kernel HIGH 7.1
CVE-2020-36386

An issue was discovered in the Linux kernel before 5.8.1. net/bluetooth/hci_event.c has a slab out-of-bounds read in hci_extended_inquiry_result_evt,…

Fix: 5.8.1+
Fix from $1,950 2021-06-07
Linux Kernel HIGH 7.8
CVE-2021-3490EPSS 27%

The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned int…

Fix: 5.10.37 / 5.11.21+
Fix from $1,950 2021-06-04
Linux Kernel HIGH 7.8
CVE-2020-35519

An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure all…

Fix: 4.4.248 / 4.9.248+
Fix from $1,950 2021-05-06
Linux Kernel MEDIUM 5.5
CVE-2021-29155

An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmeti…

Fix: 5.11.16+
Fix from $1,600 2021-04-20
Linux Kernel HIGH 7.1
CVE-2021-3506

An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds …

Fix: 5.12+
Fix from $1,950 2021-04-19
Linux Kernel HIGH 7.8
CVE-2021-3444

The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A loca…

Fix: 5.4.101 / 5.10.19+
Fix from $1,950 2021-03-23
Linux Kernel HIGH 7.1
CVE-2021-27364

An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileg…

Fix: 4.4.260 / 4.9.260+
Fix from $1,950 2021-03-07
Linux Kernel MEDIUM 5.0
CVE-2020-28974

A slab-out-of-bounds read in fbcon in the Linux kernel before 5.9.7 could be used by local attackers to read privileged information or potentially cr…

Fix: 5.9.7+
Fix from $1,600 2020-11-20
Linux Kernel MEDIUM 5.8
CVE-2020-28915

A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local attackers to read kernel mem…

Fix: 5.8.15+
Fix from $1,600 2020-11-18
Linux Kernel MEDIUM 5.5
CVE-2020-14314

A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a directory with…

Fix: after 5.8.9
Fix from $1,600 2020-09-15
Linux Kernel MEDIUM 6.5
CVE-2020-13143

gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibil…

Fix: after 5.6.13
Fix from $1,600 2020-05-18
Linux Kernel HIGH 7.8
CVE-2020-8835EPSS 6%

In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, le…

Fix: 5.4.29 / 5.5.14+
Fix from $1,950 2020-04-02
Linux Kernel HIGH 7.1
CVE-2020-9383

An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read becaus…

Fix: after 5.5.6
Fix from $1,950 2020-02-25
Linux Kernel MEDIUM 6.0
CVE-2019-19927

In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesystem image and performing some…

Patch available
Fix from $1,600 2019-12-31
Linux Kernel HIGH 7.8
CVE-2019-19449

In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f…

No fix yet
Fix from $1,950 2019-12-08
Linux Kernel HIGH 7.8
CVE-2019-19252

vcs_write in drivers/tty/vt/vc_screen.c in the Linux kernel through 5.3.13 does not prevent write access to vcsu devices, aka CID-0c9acb1af77a.

Fix: after 5.3.13
Fix from $1,950 2019-11-25
Linux Kernel CRITICAL 9.1
CVE-2014-3180

In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible out-of-bounds read. restart_s…

Fix: 3.17+
Fix from $2,300 2019-11-06
Linux Kernel CRITICAL 9.1
CVE-2019-15926EPSS 5%

An issue was discovered in the Linux kernel before 5.2.3. Out of bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx and ath6kl…

Fix: 3.16.74 / 4.4.187+
Fix from $2,300 2019-09-04
Linux Kernel HIGH 7.8
CVE-2019-15927

An issue was discovered in the Linux kernel before 4.20.2. An out-of-bounds access exists in the function build_audio_procunit in the file sound/usb/…

Fix: 3.16.66 / 3.18.132+
Fix from $1,950 2019-09-04
Linux Kernel HIGH 7.8
CVE-2019-15925

An issue was discovered in the Linux kernel before 5.2.3. An out of bounds access exists in the function hclge_tm_schd_mode_vnet_base_cfg in the file…

Fix: 4.14.135 / 4.19.61+
Fix from $1,950 2019-09-04
Linux Kernel HIGH 7.8
CVE-2019-15918

An issue was discovered in the Linux kernel before 5.0.10. SMB2_negotiate in fs/cifs/smb2pdu.c has an out-of-bounds read because data structures are …

Fix: 4.14.166 / 4.19.73+
Fix from $1,950 2019-09-04
Linux Kernel CRITICAL 9.8
CVE-2019-15505EPSS 8%

drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through 5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be r…

Fix: 3.16.77 / 4.4.194+
Fix from $2,300 2019-08-23
Linux Kernel MEDIUM 6.7
CVE-2019-15090

An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-…

Fix: 5.1.12+
Fix from $1,600 2019-08-16
Linux Kernel MEDIUM 5.5
CVE-2015-9289

In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size …

Fix: 4.1.4+
Fix from $1,600 2019-07-27
Linux Kernel MEDIUM 6.8
CVE-2019-14283

In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c does not validate the sect and head fields, as demonstrated by an integer ov…

Fix: 5.2.3+
Fix from $1,600 2019-07-26
Linux Kernel HIGH 7.8
CVE-2018-20854

An issue was discovered in the Linux kernel before 4.20. drivers/phy/mscc/phy-ocelot-serdes.c has an off-by-one error with a resultant ctrl->phys out…

Fix: 4.20+
Fix from $1,950 2019-07-26
Linux Kernel MEDIUM 6.5
CVE-2019-3459

A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.

Fix: after 5.1
Fix from $1,600 2019-04-11
Linux Kernel MEDIUM 5.5
CVE-2018-16885

A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buffer leng…

Fix: after 3.10.90
Fix from $1,600 2019-01-03
Linux Kernel HIGH 7.8
CVE-2018-18445

In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-o…

Fix: 4.14.75 / 4.18.13+
Fix from $1,950 2018-10-17
Linux Kernel HIGH 7.8
CVE-2018-15471

An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as used in Xen through 4.11.…

Fix: 4.9.133 / 4.14.76+
Fix from $1,950 2018-08-17