Vulnerability index

Browse CVEs

97 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Linux Kernel MEDIUM 5.5
CVE-2018-16862

A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removal). The n…

Fix: after 4.14
Fix from $1,600 2018-11-26
Linux Kernel MEDIUM 5.5
CVE-2018-18710

An issue was discovered in the Linux kernel through 4.19. An information leak in cdrom_ioctl_select_disc in drivers/cdrom/cdrom.c could be used by lo…

Fix: after 4.19
Fix from $1,600 2018-10-29
Linux Kernel MEDIUM 6.1
CVE-2018-16658

An issue was discovered in the Linux kernel before 4.18.6. An information leak in cdrom_ioctl_drive_status in drivers/cdrom/cdrom.c could be used by …

Fix: 4.18.6+
Fix from $1,600 2018-09-07
Linux Kernel MEDIUM 5.5
CVE-2018-5953

The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by re…

Fix: after 4.14.14
Fix from $1,600 2018-08-07
Linux Kernel MEDIUM 5.5
CVE-2018-5995

The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by …

Fix: after 4.14.14
Fix from $1,600 2018-08-07
Linux Kernel MEDIUM 5.5
CVE-2018-11508

The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel mem…

Fix: 4.16.9+
Fix from $1,600 2018-05-28
Linux Kernel MEDIUM 5.5
CVE-2018-1118

Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in t…

Fix: 4.18+
Fix from $1,600 2018-05-10
Linux Kernel MEDIUM 5.5
CVE-2018-7755

An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kernel through 4.15.7. The floppy driver will copy a k…

Fix: after 4.15.7
Fix from $1,600 2018-03-08
Linux Kernel MEDIUM 5.5
CVE-2018-7273

In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables using printk calls within the fu…

Fix: after 4.15.4
Fix from $1,600 2018-02-21
Linux Kernel HIGH 7.5
CVE-2018-6412

In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary…

Fix: after 4.15
Fix from $1,950 2018-01-31
Linux Kernel MEDIUM 5.5
CVE-2018-5750

The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows local users to obtain sensitive address information…

Fix: after 4.14.15
Fix from $1,600 2018-01-26
Linux Kernel HIGH 7.5
CVE-2017-1000410

The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and Conf…

Fix: 4.15+
Fix from $1,950 2017-12-07
Linux Kernel MEDIUM 5.5
CVE-2017-16994

The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to ob…

Fix: 4.14.2+
Fix from $1,600 2017-11-27
Linux Kernel MEDIUM 5.5
CVE-2017-15537

The x86/fpu (Floating Point Unit) subsystem in the Linux kernel before 4.13.5, when a processor supports the xsave feature but not the xsaves feature…

Fix: after 4.13.4
Fix from $1,600 2017-10-17
Linux Kernel MEDIUM 5.5
CVE-2017-14991

The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel before 4.13.4 allows local users to obtain sensitive information from uninitialized ke…

Fix: after 4.13.3
Fix from $1,600 2017-10-04
Linux Kernel MEDIUM 5.5
CVE-2017-14954

The waitid implementation in kernel/exit.c in the Linux kernel through 4.13.4 accesses rusage data structures in unintended cases, which allows local…

Fix: after 4.13.4
Fix from $1,600 2017-10-02
Linux Kernel MEDIUM 5.5
CVE-2017-14156

The atyfb_ioctl function in drivers/video/fbdev/aty/atyfb_base.c in the Linux kernel through 4.12.10 does not initialize a certain data structure, wh…

Fix: after 4.12.10
Fix from $1,600 2017-09-05
Linux Kernel MEDIUM 5.5
CVE-2017-14140

The move_pages system call in mm/migrate.c in the Linux kernel before 4.12.9 doesn't check the effective uid of the target process, enabling a local …

Fix: after 4.12.8
Fix from $1,600 2017-09-05
Linux Kernel MEDIUM 5.5
CVE-2017-13693

The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the operand cache and cause…

Fix: after 4.12.9
Fix from $1,600 2017-08-25
Linux Kernel MEDIUM 5.5
CVE-2017-13694

The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not flush the node and node_ext ca…

Fix: after 4.12.9
Fix from $1,600 2017-08-25
Linux Kernel MEDIUM 5.5
CVE-2017-13695

The acpi_ns_evaluate() function in drivers/acpi/acpica/nseval.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kern…

Fix: after 4.12.9
Fix from $1,600 2017-08-25
Linux Kernel MEDIUM 6.5
CVE-2017-10911

The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive informa…

Fix: after 4.11.7
Fix from $1,600 2017-07-05
Linux Kernel MEDIUM 5.5
CVE-2017-1000380

sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being ab…

Fix: after 4.11.4
Fix from $1,600 2017-06-17
Linux Kernel MEDIUM 5.5
CVE-2017-9605

The vmw_gb_surface_define_ioctl function (accessible via DRM_IOCTL_VMW_GB_SURFACE_CREATE) in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux ker…

Fix: after 4.11.4
Fix from $1,600 2017-06-13
Linux Kernel MEDIUM 5.5
CVE-2017-9150

The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value available for restricting th…

Fix: after 4.10.9
Fix from $1,600 2017-05-22
Linux Kernel MEDIUM 5.5
CVE-2017-7495

fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-before-commit list, which allows l…

Fix: after 4.6.1
Fix from $1,600 2017-05-15
Linux Kernel MEDIUM 5.5
CVE-2017-0624

An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permiss…

Patch available
Fix from $1,600 2017-05-12
Linux Kernel MEDIUM 5.5
CVE-2017-0626

An information disclosure vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to access data outside of its…

Patch available
Fix from $1,600 2017-05-12
Linux Kernel HIGH 7.8
CVE-2017-0455

An information disclosure vulnerability in the Qualcomm bootloader could help to enable a local malicious application to to execute arbitrary code wi…

Patch available
Fix from $1,950 2017-03-08
Linux Kernel MEDIUM 5.5
CVE-2016-8483

An information disclosure vulnerability in the Qualcomm power driver could enable a local malicious application to access data outside of its permiss…

Patch available
Fix from $1,600 2017-03-08