Vulnerability index

Browse CVEs

116 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Linux Kernel MEDIUM 5.5
CVE-2017-18200

The f2fs implementation in the Linux kernel before 4.14 mishandles reference counts associated with f2fs_wait_discard_bios calls, which allows local …

Fix: after 4.13
Fix from $1,600 2018-02-26
Linux Kernel HIGH 7.7
CVE-2018-1000026

Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card d…

Fix: 4.4.181 / 4.9.159+
Fix from $1,950 2018-02-09
Linux Kernel MEDIUM 5.5
CVE-2017-17862

kernel/bpf/verifier.c in the Linux kernel through 4.14.8 ignores unreachable code, even though it would still be processed by JIT compilers. This beh…

Fix: after 4.14.8
Fix from $1,600 2017-12-27
Linux Kernel HIGH 7.8
CVE-2017-17805

The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to us…

Fix: 3.2.97 / 3.16.52+
Fix from $1,950 2017-12-20
Linux Kernel HIGH 7.8
CVE-2017-15868

The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, whic…

Fix: 3.2.97 / 3.10.108+
Fix from $1,950 2017-12-05
Linux Kernel MEDIUM 6.6
CVE-2017-16538

drivers/media/usb/dvb-usb-v2/lmedm04.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (general protection fault …

Fix: after 4.13.11
Fix from $1,600 2017-11-04
Linux Kernel HIGH 7.8
CVE-2017-15951

The KEYS subsystem in the Linux kernel before 4.13.10 does not correctly synchronize the actions of updating versus finding a key in the "negative" s…

Fix: 4.4.95 / 4.9.59+
Fix from $1,950 2017-10-28
Linux Kernel MEDIUM 5.5
CVE-2017-1000252

The KVM subsystem in the Linux kernel through 4.13.3 allows guest OS users to cause a denial of service (assertion failure, and hypervisor hang or cr…

Fix: after 4.13.3
Fix from $1,600 2017-09-26
Linux Kernel MEDIUM 5.5
CVE-2017-14489

The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to cause a denial of service (p…

Fix: after 4.13.2
Fix from $1,600 2017-09-15
Linux Kernel MEDIUM 5.5
CVE-2017-9242

The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel through 4.11.3 is too late in checking whether an overwrite of an skb dat…

Fix: after 4.11.3
Fix from $1,600 2017-05-27
Linux Kernel HIGH 7.0
CVE-2017-0613

An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application t…

Patch available
Fix from $1,950 2017-05-12
Linux Kernel HIGH 7.0
CVE-2017-0620

An elevation of privilege vulnerability in the Qualcomm Secure Channel Manager driver could enable a local malicious application to execute arbitrary…

Fix: after 7.1.2
Fix from $1,950 2017-05-12
Linux Kernel HIGH 7.8
CVE-2017-7979

The cookie feature in the packet action API implementation in net/sched/act_api.c in the Linux kernel 4.11.x through 4.11-rc7 mishandles the tb nlatt…

Patch available
Fix from $1,950 2017-04-19
Linux Kernel HIGH 7.5
CVE-2017-7645EPSS 6%

The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a denial of service (system crash) …

Fix: 3.2.89 / 3.10.107+
Fix from $1,950 2017-04-18
Linux Kernel MEDIUM 5.5
CVE-2017-7346

The vmw_gb_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.7 does not validate certain leve…

Fix: after 4.10.7
Fix from $1,600 2017-03-30
Linux Kernel MEDIUM 5.5
CVE-2017-7261

The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.5 does not check for a zero value o…

Fix: after 4.10.5
Fix from $1,600 2017-03-24
Linux Kernel HIGH 7.0
CVE-2017-0458

An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the…

Patch available
Fix from $1,950 2017-03-08
Linux Kernel HIGH 7.0
CVE-2017-0463

An elevation of privilege vulnerability in the Qualcomm networking driver could enable a local malicious application to execute arbitrary code within…

Patch available
Fix from $1,950 2017-03-08
Linux Kernel HIGH 7.8
CVE-2017-6345

The LLC subsystem in the Linux kernel before 4.9.13 does not ensure that a certain destructor exists in required circumstances, which allows local us…

Fix: after 4.9.12
Fix from $1,950 2017-03-01
Linux Kernel MEDIUM 5.5
CVE-2010-5328

include/linux/init_task.h in the Linux kernel before 2.6.35 does not prevent signals with a process group ID of zero from reaching the swapper proces…

Fix: after 2.6.34.7
Fix from $1,600 2017-02-06
Linux Kernel CRITICAL 9.8
CVE-2016-8437

Improper input validation in Access Control APIs. Access control API may return memory range checking incorrectly. Product: Android. Versions: Kernel…

Mitigation only
Fix from $2,300 2017-01-12
Linux Kernel HIGH 7.8
CVE-2016-8442

Possible unauthorized memory access in the hypervisor. Lack of input validation could allow hypervisor memory to be accessed by the HLOS. Product: An…

Mitigation only
Fix from $1,950 2017-01-12
Linux Kernel HIGH 7.5
CVE-2016-9919EPSS 6%

The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote at…

Fix: 4.9+
Fix from $1,950 2016-12-08
Linux Kernel MEDIUM 5.5
CVE-2016-9191

The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial …

Fix: after 4.8.11
Fix from $1,600 2016-11-28
Linux Kernel MEDIUM 5.5
CVE-2016-8650

The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows lo…

Fix: after 4.8.11
Fix from $1,600 2016-11-28
Linux Kernel HIGH 7.8
CVE-2015-3288

mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or cause a denial of service (pa…

Fix: 3.2.71 / 3.4.111+
Fix from $1,950 2016-10-16
Linux Kernel HIGH 7.8
CVE-2016-5340

The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x…

Fix: after 7.0
Fix from $1,950 2016-08-07
Linux Kernel CRITICAL 9.8
CVE-2014-9410

The vfe31_proc_general function in drivers/media/video/msm/vfe/msm_vfe31.c in the MSM-VFE31 driver for the Linux kernel 3.x, as used in Qualcomm Inno…

Fix: after 3.19.8
Fix from $2,300 2016-08-07
Linux Kernel HIGH 7.8
CVE-2016-6162

net/core/skbuff.c in the Linux kernel 4.7-rc6 allows local users to cause a denial of service (panic) or possibly have unspecified other impact via c…

Mitigation only
Fix from $1,950 2016-08-06
Linux Kernel HIGH 7.8
CVE-2016-5828

The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, whi…

Fix: 3.10.103 / 3.14.74+
Fix from $1,950 2016-06-27