Vulnerability index

Browse CVEs

116 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Linux Kernel MEDIUM 5.4
CVE-2011-1079

The bnep_sock_ioctl function in net/bluetooth/bnep/sock.c in the Linux kernel before 2.6.39 does not ensure that a certain device field ends with a '…

Fix: after 2.6.38.8
Fix from $1,600 2012-06-21
Linux Kernel MEDIUM 6.5
CVE-2011-3363

The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS se…

Fix: 2.6.39+
Fix from $1,600 2012-05-24
Linux Kernel MEDIUM 5.5
CVE-2012-1090

The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted acce…

Fix: 3.2.10+
Fix from $1,600 2012-05-17
Linux Kernel MEDIUM 5.7
CVE-2011-2723

The skb_gro_header_slow function in include/linux/netdevice.h in the Linux kernel before 2.6.39.4, when Generic Receive Offload (GRO) is enabled, res…

Fix: 2.6.39.4+
Fix from $1,600 2011-09-06
Linux Kernel HIGH 9.0
CVE-2011-1581

The bond_select_queue function in drivers/net/bonding/bond_main.c in the Linux kernel before 2.6.39, when a network device with a large number of rec…

Fix: 2.6.39+
Fix from $1,950 2011-05-26
Linux Kernel MEDIUM 6.9
CVE-2011-2022

The agp_generic_remove_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 does not validate a certain start parameter,…

Fix: 2.6.38.5+
Fix from $1,600 2011-05-09
Linux Kernel HIGH 7.2
CVE-2011-1495

drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier does not validate (1) length and (2) offset values before performing memory…

Fix: after 2.6.38
Fix from $1,950 2011-05-03
Linux Kernel HIGH 7.2
CVE-2010-2962

drivers/gpu/drm/i915/i915_gem.c in the Graphics Execution Manager (GEM) in the Intel i915 driver in the Direct Rendering Manager (DRM) subsystem in t…

Fix: 2.6.36+
Fix from $1,950 2010-11-26
Linux Kernel MEDIUM 6.2
CVE-2010-2963

drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not vali…

Fix: 2.6.36+
Fix from $1,600 2010-11-26
Linux Kernel HIGH 7.8
CVE-2010-3432EPSS 6%

The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs extraneous initializations of packet data structure…

Fix: 2.6.35.6+
Fix from $1,950 2010-11-22
Linux Kernel HIGH 7.8
CVE-2010-2248

fs/cifs/cifssmb.c in the CIFS implementation in the Linux kernel before 2.6.34-rc4 allows remote attackers to cause a denial of service (panic) via a…

Fix: after 2.6.34
Fix from $1,950 2010-09-07
Linux Kernel HIGH 7.1
CVE-2010-1173EPSS 21%

The sctp_process_unk_param function in net/sctp/sm_make_chunk.c in the Linux kernel 2.6.33.3 and earlier, when SCTP is enabled, allows remote attacke…

Fix: after 2.6.33.3
Fix from $1,950 2010-05-07
Linux Kernel HIGH 7.8
CVE-2010-0741

The virtio_net_bad_features function in hw/virtio-net.c in the virtio-net driver in the Linux kernel before 2.6.26, when used on a guest OS in conjun…

Mitigation only
Fix from $1,950 2010-04-12
Linux Kernel HIGH 7.8
CVE-2009-4537EPSS 6%

drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds t…

Fix: after 2.6.32.3
Fix from $1,950 2010-01-12
Linux Kernel HIGH 7.8
CVE-2009-4031

The do_insn_fetch function in arch/x86/kvm/emulate.c in the x86 emulator in the KVM subsystem in the Linux kernel before 2.6.32-rc8-next-20091125 tri…

Fix: 2.6.32+
Fix from $1,950 2009-11-29
Linux Kernel HIGH 7.2
CVE-2009-0029

The ABI in the Linux kernel 2.6.28 and earlier on s390, powerpc, sparc64, and mips 64-bit platforms requires that a 32-bit argument in a 64-bit regis…

Fix: after 2.6.28
Fix from $1,950 2009-01-15
Linux Kernel HIGH 7.8
CVE-2008-4934

The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_…

Fix: 2.6.28+
Fix from $1,950 2008-11-05
Linux Kernel HIGH 7.8
CVE-2008-4618

The Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.27 does not properly handle a protocol violation in whi…

Fix: after 2.6.26.5
Fix from $1,950 2008-10-21
Direct Connect HIGH 7.8
CVE-2008-2954

client/NmdcHub.cpp in Linux DC++ (linuxdcpp) before 0.707 allows remote attackers to cause a denial of service (crash) via an empty private message, …

No fix yet
Fix from $1,950 2008-07-01
Direct Connect MEDIUM 5.0
CVE-2008-2953

Linux DC++ (linuxdcpp) before 0.707 allows remote attackers to cause a denial of service (crash) via "partial file list requests" that trigger a NULL…

No fix yet
Fix from $1,600 2008-07-01
Linux Kernel HIGH 7.8
CVE-2008-2750

The pppol2tp_recvmsg function in drivers/net/pppol2tp.c in the Linux kernel 2.6 before 2.6.26-rc6 allows remote attackers to cause a denial of servic…

Patch available
Fix from $1,950 2008-06-18
Linux Kernel HIGH 7.8
CVE-2007-4567EPSS 14%

The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, w…

Fix: after 2.6.21.7
Fix from $1,950 2007-12-21
Linux Kernel HIGH 7.8
CVE-2007-2764

The embedded Linux kernel in certain Sun-Brocade SilkWorm switches before 20070516 does not properly handle a situation in which a non-root user crea…

Patch available
Fix from $1,950 2007-05-18
Linux Kernel HIGH 7.8
CVE-2006-1858EPSS 6%

SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a chunk le…

Mitigation only
Fix from $1,950 2006-05-22
Linux Kernel HIGH 7.8
CVE-2005-0209

Netfilter in Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via crafted IP packet fragments.

Patch available
Fix from $1,950 2005-05-02
Linux Kernel HIGH 7.1
CVE-2005-0449

The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules vi…

Patch available
Fix from $1,950 2005-05-02