Vulnerability index

Browse CVEs

116 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Linux Kernel HIGH 7.8
CVE-2015-8019

The skb_copy_and_csum_datagram_iovec function in net/core/datagram.c in the Linux kernel 3.14.54 and 3.18.22 does not accept a length argument, which…

Mitigation only
Fix from $1,950 2016-05-02
Linux Kernel MEDIUM 5.5
CVE-2015-2672

The xsave/xrstor implementation in arch/x86/include/asm/xsave.h in the Linux kernel before 3.19.2 creates certain .altinstr_replacement pointers and …

Fix: after 3.19.1
Fix from $1,600 2016-05-02
Linux Kernel MEDIUM 5.5
CVE-2008-7316

mm/filemap.c in the Linux kernel before 2.6.25 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers…

Fix: after 2.6.24
Fix from $1,600 2016-05-02
Linux Kernel MEDIUM 6.2
CVE-2016-2548

sound/core/timer.c in the Linux kernel before 4.4.1 retains certain linked lists after a close or stop action, which allows local users to cause a de…

Fix: after 4.4
Fix from $1,600 2016-04-27
Linux Kernel MEDIUM 6.2
CVE-2016-2549

sound/core/hrtimer.c in the Linux kernel before 4.4.1 does not prevent recursive callback access, which allows local users to cause a denial of servi…

Fix: after 4.4
Fix from $1,600 2016-04-27
Linux Kernel HIGH 7.8
CVE-2016-2143

The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, which allows local users to c…

Fix: 3.2.79 / 3.12.58+
Fix from $1,950 2016-04-27
Linux Kernel MEDIUM 6.8
CVE-2016-0774

The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in a certain Linux kernel backport in the linux package before 3.2.73-2+deb7u3 on D…

Fix: after 6.0.1
Fix from $1,600 2016-04-27
Linux Kernel MEDIUM 5.5
CVE-2015-8844

The signal implementation in the Linux kernel before 4.3.5 on powerpc platforms does not check for an MSR with both the S and T bits set, which allow…

Fix: after 4.3.4
Fix from $1,600 2016-04-27
Linux Kernel MEDIUM 5.0
CVE-2015-8215

net/ipv6/addrconf.c in the IPv6 stack in the Linux kernel before 4.0 does not validate attempted changes to the MTU value, which allows context-depen…

Fix: after 3.19
Fix from $1,600 2015-11-16
Linux Kernel MEDIUM 5.0
CVE-2014-8160EPSS 5%

net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables …

Fix: 3.18+
Fix from $1,600 2015-03-02
Linux Kernel HIGH 7.5
CVE-2014-4323

The mdp_lut_hw_update function in drivers/video/msm/mdp.c in the MDP display driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (…

Fix: after 3.16.1
Fix from $1,950 2014-12-12
Linux Kernel HIGH 7.5
CVE-2014-3673EPSS 7%

The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF…

Fix: 3.2.64 / 3.4.107+
Fix from $1,950 2014-11-10
Linux Kernel MEDIUM 5.0
CVE-2014-4611EPSS 8%

Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decomp…

Fix: 3.15.2+
Fix from $1,600 2014-07-03
Linux Kernel MEDIUM 5.5
CVE-2014-0155

The ioapic_deliver function in virt/kvm/ioapic.c in the Linux kernel through 3.14.1 does not properly validate the kvm_irq_delivery_to_apic return va…

Fix: 3.14.1+
Fix from $1,600 2014-04-14
Linux Kernel HIGH 10.0
CVE-2014-2523EPSS 10%

net/netfilter/nf_conntrack_proto_dccp.c in the Linux kernel through 3.13.6 uses a DCCP header pointer incorrectly, which allows remote attackers to c…

Fix: 3.2.57 / 3.4.86+
Fix from $1,950 2014-03-24
Linux Kernel MEDIUM 6.9
CVE-2014-0038EPSS 35%

The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privil…

Fix: 3.4.79 / 3.10.29+
Fix from $1,600 2014-02-06
Linux Kernel HIGH 7.2
CVE-2013-4587

Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows loca…

Fix: 3.2.54 / 3.4.75+
Fix from $1,950 2013-12-14
Linux Kernel MEDIUM 6.2
CVE-2013-6368

The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC sy…

Fix: after 3.12.5
Fix from $1,600 2013-12-14
Linux Kernel HIGH 8.8
CVE-2013-6282 KEVEPSS 40%

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, w…

Fix: 3.2.54 / 3.4.12+
Fix from $1,950 2013-11-20
Linux Kernel MEDIUM 6.2
CVE-2013-2888

Multiple array index errors in drivers/hid/hid-core.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11 allow physically…

Fix: after 3.11
Fix from $1,600 2013-09-16
Linux Kernel MEDIUM 6.9
CVE-2013-4254

The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel before 3.10.8 on the ARM platform allows local users to gain privileg…

Fix: after 3.10.7
Fix from $1,600 2013-08-25
Linux Kernel HIGH 7.8
CVE-2013-1943

The KVM subsystem in the Linux kernel before 3.0 does not check whether kernel addresses are specified during allocation of memory slots for use in a…

Fix: 3.0+
Fix from $1,950 2013-07-16
Linux Kernel MEDIUM 6.9
CVE-2013-1828

The sctp_getsockopt_assoc_stats function in net/sctp/socket.c in the Linux kernel before 3.8.4 does not validate a size value before proceeding to a …

Fix: 3.8.4+
Fix from $1,600 2013-03-22
Linux Kernel MEDIUM 6.2
CVE-2013-1798

The ioapic_read_indirect function in virt/kvm/ioapic.c in the Linux kernel through 3.8.4 does not properly handle a certain combination of invalid IO…

Fix: after 3.8.4
Fix from $1,600 2013-03-22
Linux Kernel MEDIUM 6.2
CVE-2013-1848

fs/ext3/super.c in the Linux kernel before 3.8.4 uses incorrect arguments to functions in certain circumstances related to printk input, which allows…

Fix: after 3.8.3
Fix from $1,600 2013-03-22
Linux Kernel HIGH 7.2
CVE-2013-1763

Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows local users to gain privileges…

Fix: 3.4.34 / 3.7.10+
Fix from $1,950 2013-02-28
Linux Kernel MEDIUM 5.2
CVE-2013-0216

The Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (loop) by triggering ring pointer c…

Fix: after 3.7.8
Fix from $1,600 2013-02-18
Linux Kernel HIGH 7.2
CVE-2012-2136

The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows…

Fix: 3.0.37 / 3.2.23+
Fix from $1,950 2012-08-09
Linux Kernel HIGH 7.8
CVE-2011-4913

The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_N…

Fix: after 2.6.38.8
Fix from $1,950 2012-06-21
Linux Kernel MEDIUM 6.4
CVE-2011-4914EPSS 9%

The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of …

Fix: after 2.6.38.8
Fix from $1,600 2012-06-21