Vulnerability index

Browse CVEs

62 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Linux Kernel MEDIUM 5.5
CVE-2019-13648

In the Linux kernel through 5.2.1 on the powerpc platform, when hardware transactional memory is disabled, a local user can cause a denial of service…

Fix: after 5.2.1
Fix from $1,600 2019-07-19
Linux Kernel MEDIUM 5.5
CVE-2016-10723

An issue was discovered in the Linux kernel through 4.17.2. Since the page allocator does not yield CPU resources to the owner of the oom_lock mutex,…

Fix: after 4.17.2
Fix from $1,600 2018-06-21
Linux Kernel MEDIUM 5.5
CVE-2014-8171

The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes w…

Mitigation only
Fix from $1,600 2018-02-09
Linux Kernel MEDIUM 5.5
CVE-2016-10292

A denial of service vulnerability in the Qualcomm Wi-Fi driver could enable a proximate attacker to cause a denial of service in the Wi-Fi subsystem.…

Patch available
Fix from $1,600 2017-05-12
Linux Kernel MEDIUM 5.5
CVE-2010-5329

The video_usercopy function in drivers/media/video/v4l2-ioctl.c in the Linux kernel before 2.6.39 relies on the count value of a v4l2_ext_controls da…

Fix: after 2.6.38.8
Fix from $1,600 2017-04-24
Linux Kernel HIGH 7.8
CVE-2016-10153

The crypto scatterlist API in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users t…

Patch available
Fix from $1,950 2017-02-06
Linux Kernel MEDIUM 5.5
CVE-2016-8463

A denial of service vulnerability in the Qualcomm FUSE file system could enable a remote attacker to use a specially crafted file to cause a device h…

Patch available
Fix from $1,600 2017-01-12
Linux Kernel MEDIUM 5.5
CVE-2016-9191

The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial …

Fix: after 4.8.11
Fix from $1,600 2016-11-28
Linux Kernel MEDIUM 5.5
CVE-2016-8650

The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows lo…

Fix: after 4.8.11
Fix from $1,600 2016-11-28
Linux Kernel MEDIUM 5.5
CVE-2015-8953

fs/overlayfs/copy_up.c in the Linux kernel before 4.2.6 uses an incorrect cleanup code path, which allows local users to cause a denial of service (d…

Fix: after 4.2.5
Fix from $1,600 2016-10-16
Linux Kernel MEDIUM 6.5
CVE-2016-5412

arch/powerpc/kvm/book3s_hv_rmhandlers.S in the Linux kernel through 4.7 on PowerPC platforms, when CONFIG_KVM_BOOK3S_64_HV is enabled, allows guest O…

Fix: after 4.7
Fix from $1,600 2016-08-06
Linux Kernel MEDIUM 6.2
CVE-2016-2847

fs/pipe.c in the Linux kernel before 4.5 does not limit the amount of unread data in pipes, which allows local users to cause a denial of service (me…

Fix: after 4.4.8
Fix from $1,600 2016-04-27
Linux Kernel MEDIUM 5.5
CVE-2016-2550

The Linux kernel before 4.5 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by leveraging inco…

Fix: after 4.4.8
Fix from $1,600 2016-04-27
Linux Kernel MEDIUM 6.2
CVE-2015-1339

Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (me…

Fix: after 4.3.6
Fix from $1,600 2016-04-27
Linux Kernel CRITICAL 10.0
CVE-2015-8104

The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic o…

Fix: after 5.0.13
Fix from $2,300 2015-11-16
Linux Kernel HIGH 7.8
CVE-2013-7445

The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which …

Fix: after 4.0.0
Fix from $1,950 2015-10-16
Linux Kernel MEDIUM 5.0
CVE-2015-5366EPSS 6%

The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 provide inappropriate -EAGAIN return values, which allows remote…

Fix: after 4.0.5
Fix from $1,600 2015-08-31
Linux Kernel HIGH 7.8
CVE-2015-5364EPSS 6%

The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 do not properly consider yielding a processor, which allows remo…

Fix: 3.2.70 / 3.4.109+
Fix from $1,950 2015-08-31
Linux Kernel HIGH 7.8
CVE-2014-9428EPSS 5%

The batadv_frag_merge_packets function in net/batman-adv/fragmentation.c in the B.A.T.M.A.N. implementation in the Linux kernel through 3.18.1 uses a…

Fix: 3.14.30 / 3.16.35+
Fix from $1,950 2015-01-02
Linux Kernel MEDIUM 5.0
CVE-2014-7841EPSS 5%

The sctp_process_param function in net/sctp/sm_make_chunk.c in the SCTP implementation in the Linux kernel before 3.17.4, when ASCONF is used, allows…

Fix: after 3.17.3
Fix from $1,600 2014-11-30
Linux Kernel MEDIUM 5.0
CVE-2014-3688EPSS 6%

The SCTP implementation in the Linux kernel before 3.17.4 allows remote attackers to cause a denial of service (memory consumption) by triggering a l…

Fix: after 3.17.3
Fix from $1,600 2014-11-30
Linux Kernel HIGH 7.8
CVE-2014-6417EPSS 5%

net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly consider the possibility of kmalloc failure, which allows rem…

Fix: 3.4.105 / 3.10.55+
Fix from $1,950 2014-09-28
Linux Kernel HIGH 7.1
CVE-2014-6418

net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause…

Fix: 3.2.64 / 3.4.105+
Fix from $1,950 2014-09-28
Linux Kernel HIGH 7.1
CVE-2013-4348EPSS 9%

The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of service (inf…

Fix: 3.2.54 / 3.4.70+
Fix from $1,950 2013-11-04
Linux Kernel MEDIUM 6.9
CVE-2013-4343

Use-after-free vulnerability in drivers/net/tun.c in the Linux kernel through 3.11.1 allows local users to gain privileges by leveraging the CAP_NET_…

Fix: 3.10.16 / 3.11.5+
Fix from $1,600 2013-09-25
Linux Kernel MEDIUM 5.4
CVE-2013-4125

The fib6_add_rt2node function in net/ipv6/ip6_fib.c in the IPv6 stack in the Linux kernel through 3.10.1 does not properly handle Router Advertisemen…

Fix: after 3.10.1
Fix from $1,600 2013-07-15
Linux Kernel MEDIUM 5.7
CVE-2011-3593

A certain Red Hat patch to the vlan_hwaccel_do_receive function in net/8021q/vlan_core.c in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL…

Mitigation only
Fix from $1,600 2013-06-08
Linux Kernel HIGH 7.8
CVE-2013-2017

The veth (aka virtual Ethernet) driver in the Linux kernel before 2.6.34 does not properly manage skbs during congestion, which allows remote attacke…

Fix: after 2.6.33.20
Fix from $1,950 2013-05-03
Linux Kernel MEDIUM 6.8
CVE-2013-1797

Use-after-free vulnerability in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 allows guest OS users to cause a denial of service (host OS memo…

Fix: after 3.8.4
Fix from $1,600 2013-03-22
Linux Kernel MEDIUM 5.5
CVE-2011-2479

The Linux kernel before 2.6.39 does not properly create transparent huge pages in response to a MAP_PRIVATE mmap system call on /dev/zero, which allo…

Fix: 2.6.39+
Fix from $1,600 2013-03-01