Vulnerability index

Browse CVEs

664 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Linux Kernel MEDIUM 5.5
CVE-2018-14610

An issue was discovered in the Linux kernel through 4.17.10. There is out-of-bounds access in write_extent_buffer() when mounting and operating a cra…

Fix: after 4.17.10
Fix from $1,600 2018-07-27
Linux Kernel MEDIUM 5.5
CVE-2017-18344

The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly validate the sigevent->sigev…

Fix: 4.14.8+
Fix from $1,600 2018-07-26
Linux Kernel HIGH 7.5
CVE-2017-7558

A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions …

Fix: after 4.13
Fix from $1,950 2018-07-26
Linux Kernel MEDIUM 5.5
CVE-2018-13096

An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.14. A denial of service (out-of-bounds memory access and BUG) can occur upon…

Fix: after 4.14
Fix from $1,600 2018-07-03
Linux Kernel MEDIUM 5.5
CVE-2018-13097

An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.17.3. There is an out-of-bounds read or a divide-by-zero error for an incorr…

Fix: after 4.17.3
Fix from $1,600 2018-07-03
Linux Kernel MEDIUM 5.5
CVE-2018-13098

An issue was discovered in fs/f2fs/inode.c in the Linux kernel through 4.17.3. A denial of service (slab out-of-bounds read and BUG) can occur for a …

Fix: after 4.17.3
Fix from $1,600 2018-07-03
Linux Kernel MEDIUM 5.5
CVE-2018-13099

An issue was discovered in fs/f2fs/inline.c in the Linux kernel through 4.4. A denial of service (out-of-bounds memory access and BUG) can occur for …

Fix: after 4.4
Fix from $1,600 2018-07-03
Linux Kernel MEDIUM 5.5
CVE-2018-1093

The ext4_valid_block_bitmap function in fs/ext4/balloc.c in the Linux kernel through 4.15.15 allows attackers to cause a denial of service (out-of-bo…

Fix: after 4.15.15
Fix from $1,600 2018-04-02
Linux Kernel MEDIUM 5.9
CVE-2017-16912

The "get_pipe()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 allows attackers to cause a de…

Fix: 4.1.49+
Fix from $1,600 2018-01-31
Linux Kernel MEDIUM 6.5
CVE-2017-17741

The KVM implementation in the Linux kernel through 4.14.7 allows attackers to obtain potentially sensitive information from kernel memory, aka a writ…

Fix: after 4.14.7
Fix from $1,600 2017-12-18
Linux Kernel HIGH 7.8
CVE-2017-6264

An elevation of privilege vulnerability exists in the NVIDIA GPU driver (gm20b_clk_throt_set_cdev_state), where an out of bound memory read is used a…

Patch available
Fix from $1,950 2017-11-14
Linux Kernel MEDIUM 6.6
CVE-2017-16643

The parse_hid_report_descriptor function in drivers/input/tablet/gtco.c in the Linux kernel before 4.13.11 allows local users to cause a denial of se…

Fix: after 4.13.11
Fix from $1,600 2017-11-07
Linux Kernel MEDIUM 6.6
CVE-2017-16645

The ims_pcu_get_cdc_union_desc function in drivers/input/misc/ims-pcu.c in the Linux kernel through 4.13.11 allows local users to cause a denial of s…

Fix: after 4.13.11
Fix from $1,600 2017-11-07
Linux Kernel MEDIUM 6.6
CVE-2017-16533

The usbhid_parse function in drivers/hid/usbhid/hid-core.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (out-of-…

Fix: 3.2.95 / 3.16.50+
Fix from $1,600 2017-11-04
Linux Kernel MEDIUM 6.6
CVE-2017-16535

The usb_get_bos_descriptor function in drivers/usb/core/config.c in the Linux kernel before 4.13.10 allows local users to cause a denial of service (…

Fix: after 4.13.9
Fix from $1,600 2017-11-04
Linux Kernel MEDIUM 6.6
CVE-2017-16529

The snd_usb_create_streams function in sound/usb/card.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bou…

Fix: 3.2.95 / 3.16.50+
Fix from $1,600 2017-11-04
Linux Kernel MEDIUM 6.6
CVE-2017-16530

The uas driver in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly ha…

Fix: 3.16.50 / 3.18.75+
Fix from $1,600 2017-11-04
Linux Kernel MEDIUM 6.5
CVE-2015-5327

Out-of-bounds memory read in the x509_decode_time function in x509_cert_parser.c in Linux kernels 4.3-rc1 and after.

Patch available
Fix from $1,600 2017-09-25
Linux Kernel HIGH 7.0
CVE-2017-11600

net/xfrm/xfrm_policy.c in the Linux kernel through 4.12.3, when CONFIG_XFRM_MIGRATE is enabled, does not ensure that the dir value of xfrm_userpolicy…

Fix: 3.2.93 / 3.10.108+
Fix from $1,950 2017-07-24
Linux Kernel HIGH 7.8
CVE-2017-9984

The snd_msnd_interrupt function in sound/isa/msnd/msnd_pinnacle.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service …

Fix: 3.18.71 / 4.1.45+
Fix from $1,950 2017-06-28
Linux Kernel HIGH 7.8
CVE-2017-9985

The snd_msndmidi_input_read function in sound/isa/msnd/msnd_midi.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service…

Fix: 3.18.71 / 4.1.45+
Fix from $1,950 2017-06-28
Linux Kernel HIGH 7.8
CVE-2017-9986

The intr function in sound/oss/msnd_pinnacle.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary acce…

Fix: after 4.11.7
Fix from $1,950 2017-06-28
Linux Kernel HIGH 7.8
CVE-2017-9074

The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid o…

Fix: 3.2.89 / 3.16.44+
Fix from $1,950 2017-05-19
Linux Kernel MEDIUM 6.4
CVE-2017-8831

The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local users to cause a denial of se…

Fix: after 4.11.5
Fix from $1,600 2017-05-08
Linux Kernel HIGH 7.1
CVE-2017-7277

The TCP stack in the Linux kernel through 4.10.6 mishandles the SCM_TIMESTAMPING_OPT_STATS feature, which allows local users to obtain sensitive info…

Fix: after 4.10.6
Fix from $1,950 2017-03-28
Linux Kernel CRITICAL 9.8
CVE-2017-5897

The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags …

Fix: 3.10.106 / 3.12.71+
Fix from $2,300 2017-03-23
Linux Kernel HIGH 7.8
CVE-2017-6347

The ip_cmsg_recv_checksum function in net/ipv4/ip_sockglue.c in the Linux kernel before 4.10.1 has incorrect expectations about skb data layout, whic…

Fix: 4.4.52 / 4.9.13+
Fix from $1,950 2017-03-01
Linux Kernel HIGH 7.8
CVE-2016-9777

KVM in the Linux kernel before 4.8.12, when I/O APIC is enabled, does not properly restrict the VCPU index, which allows guest OS users to gain host …

Fix: 4.8.12+
Fix from $1,950 2016-12-28
Linux Kernel CRITICAL 9.8
CVE-2016-9555EPSS 9%

The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows r…

Fix: 3.2.85 / 3.10.105+
Fix from $2,300 2016-11-28
Linux Kernel MEDIUM 5.0
CVE-2016-7917

The nfnetlink_rcv_batch function in net/netfilter/nfnetlink.c in the Linux kernel before 4.5 does not check whether a batch message's length field is…

Fix: after 4.4.32
Fix from $1,600 2016-11-16