Vulnerability index

Browse CVEs

194 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Linux Kernel HIGH 7.8
CVE-2019-18675

The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c because cpia2 …

Fix: 3.16.60 / 3.18.113+
Fix from $1,950 2019-11-25
Linux Kernel CRITICAL 9.8
CVE-2019-18805

An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in t…

Fix: 4.4.180 / 4.9.172+
Fix from $2,300 2019-11-07
Linux Kernel HIGH 7.8
CVE-2019-10142

A flaw was found in the Linux kernel's freescale hypervisor manager implementation, kernel versions 5.0.x up to, excluding 5.0.17. A parameter passed…

Fix: 5.0.17+
Fix from $1,950 2019-07-30
Linux Kernel MEDIUM 6.8
CVE-2019-14283

In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c does not validate the sect and head fields, as demonstrated by an integer ov…

Fix: 5.2.3+
Fix from $1,600 2019-07-26
Linux Kernel HIGH 7.5
CVE-2019-11477EPSS 99%

Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Sele…

Fix: 3.16.69 / 4.4.182+
Fix from $1,950 2019-06-19
Linux Kernel HIGH 7.8
CVE-2017-7482

In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lea…

Fix: 3.2.90 / 3.10.108+
Fix from $1,950 2018-07-30
Linux Kernel HIGH 7.8
CVE-2018-13406

An integer overflow in the uvesafb_setcmap function in drivers/video/fbdev/uvesafb.c in the Linux kernel before 4.17.4 could result in local attacker…

Fix: 3.16.58 / 3.18.114+
Fix from $1,950 2018-07-06
Linux Kernel MEDIUM 5.5
CVE-2018-12896

An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by th…

Fix: after 4.17.3
Fix from $1,600 2018-07-02
Linux Kernel HIGH 7.8
CVE-2018-8781

The udl_fb_mmap function in drivers/gpu/drm/udl/udl_fb.c at the Linux kernel version 3.4 and up to and including 4.15 has an integer-overflow vulnera…

Fix: 3.16.57 / 3.18.103+
Fix from $1,950 2018-04-23
Linux Kernel MEDIUM 5.5
CVE-2017-18257

The __get_data_block function in fs/f2fs/data.c in the Linux kernel before 4.11 allows local users to cause a denial of service (integer overflow and…

Fix: 4.11+
Fix from $1,600 2018-04-04
Linux Kernel HIGH 7.8
CVE-2017-18255

The perf_cpu_time_max_percent_handler function in kernel/events/core.c in the Linux kernel before 4.11 allows local users to cause a denial of servic…

Fix: 4.11+
Fix from $1,950 2018-03-31
Linux Kernel HIGH 7.8
CVE-2018-6927

The futex_requeue function in kernel/futex.c in the Linux kernel before 4.14.15 might allow attackers to cause a denial of service (integer overflow)…

Fix: 4.14.15+
Fix from $1,950 2018-02-12
Linux Kernel HIGH 7.8
CVE-2017-17854

kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (integer overflow and memory corruption) or …

Fix: 4.14.9+
Fix from $1,950 2017-12-27
Linux Kernel HIGH 7.8
CVE-2017-17863

kernel/bpf/verifier.c in the Linux kernel 4.9.x through 4.9.71 does not check the relationship between pointer values and the BPF stack, which allows…

Fix: after 4.9.71
Fix from $1,950 2017-12-27
Linux Kernel MEDIUM 5.5
CVE-2017-7542

The ip6_find_1stfragopt function in net/ipv6/output_core.c in the Linux kernel through 4.12.3 allows local users to cause a denial of service (intege…

Fix: after 4.12.3
Fix from $1,600 2017-07-21
Linux Kernel HIGH 7.0
CVE-2017-0611

An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the …

Patch available
Fix from $1,950 2017-05-12
Linux Kernel HIGH 7.0
CVE-2017-0576

An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code wit…

Patch available
Fix from $1,950 2017-04-07
Linux Kernel HIGH 7.8
CVE-2017-7294

The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.6 does not validate addition of cer…

Fix: 3.2.89 / 3.10.107+
Fix from $1,950 2017-03-29
Linux Kernel HIGH 7.0
CVE-2017-0521

An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the…

Patch available
Fix from $1,950 2017-03-08
Linux Kernel HIGH 7.8
CVE-2017-0307

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the cont…

Patch available
Fix from $1,950 2017-03-08
Linux Kernel HIGH 7.8
CVE-2016-8636

Integer overflow in the mem_check_range function in drivers/infiniband/sw/rxe/rxe_mr.c in the Linux kernel before 4.9.10 allows local users to cause …

Fix: 4.9.10+
Fix from $1,950 2017-02-22
Linux Kernel HIGH 7.8
CVE-2017-5576

Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 allows loc…

Fix: 4.9.7+
Fix from $1,950 2017-02-06
Linux Kernel CRITICAL 9.8
CVE-2016-8438

Integer overflow leading to a TOCTOU condition in hypervisor PIL. An integer overflow exposes a race condition that may be used to bypass (Peripheral…

Mitigation only
Fix from $2,300 2017-01-12
Linux Kernel HIGH 7.8
CVE-2016-9754

The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.1 mishandles certain integer …

Fix: 3.10.102 / 3.12.61+
Fix from $1,950 2017-01-05
Linux Kernel HIGH 7.8
CVE-2016-9084

drivers/vfio/pci/vfio_pci_intrs.c in the Linux kernel through 4.8.11 misuses the kzalloc function, which allows local users to cause a denial of serv…

Fix: after 4.8.11
Fix from $1,950 2016-11-28
Linux Kernel HIGH 7.8
CVE-2016-9083

drivers/vfio/pci/vfio_pci.c in the Linux kernel through 4.8.11 allows local users to bypass integer overflow checks, and cause a denial of service (m…

Fix: 3.10.107 / 3.12.70+
Fix from $1,950 2016-11-28
Linux Kernel CRITICAL 9.8
CVE-2016-5344

Multiple integer overflows in the MDSS driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM de…

Fix: after 7.0
Fix from $2,300 2016-08-30
Linux Kernel HIGH 7.8
CVE-2016-2068

The MSM QDSP6 audio driver (aka sound driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM de…

Fix: after 6.0.1
Fix from $1,950 2016-07-11
Linux Kernel HIGH 7.8
CVE-2012-6703

Integer overflow in the snd_compr_allocate_buffer function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.6-rc6-…

Fix: 3.7+
Fix from $1,950 2016-06-29
Linux Kernel HIGH 7.8
CVE-2016-2062

The adreno_perfcounter_query_group function in drivers/gpu/msm/adreno_perfcounter.c in the Adreno GPU driver for the Linux kernel 3.x, as used in Qua…

Fix: after 3.19.8
Fix from $1,950 2016-05-05