Vulnerability index

Browse CVEs

1,622 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Linux Kernel HIGH 8.8
CVE-2018-16882

A use-after-free issue was found in the way the Linux kernel's KVM hypervisor processed posted interrupts when nested(=1) virtualization is enabled. …

Fix: 4.14.91 / 4.19.13+
Fix from $1,950 2019-01-03
Linux Kernel HIGH 8.0
CVE-2018-16884

A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_proce…

Fix: 3.16.65 / 3.18.133+
Fix from $1,950 2018-12-18
Linux Kernel HIGH 7.8
CVE-2018-19824

In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malicious USB Sound device (with ze…

Fix: after 4.19.6
Fix from $1,950 2018-12-03
Linux Kernel HIGH 8.1
CVE-2018-18559

In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt and bind on an AF_PACKET sock…

Fix: 3.2.100 / 3.15+
Fix from $1,950 2018-10-22
Linux Kernel HIGH 7.8
CVE-2018-17182

An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An…

Fix: 3.16.58 / 3.18.123+
Fix from $1,950 2018-09-19
Linux Kernel HIGH 7.0
CVE-2018-14625

A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condi…

Patch available
Fix from $1,950 2018-09-10
Linux Kernel HIGH 7.8
CVE-2018-6555

The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users…

Fix: 4.17+
Fix from $1,950 2018-09-04
Linux Kernel HIGH 7.8
CVE-2018-14619

A flaw was found in the crypto subsystem of the Linux kernel before version kernel-4.15-rc4. The "null skcipher" was being dropped when each af_alg_c…

Fix: 4.14.8+
Fix from $1,950 2018-08-30
Linux Kernel HIGH 7.8
CVE-2018-14734

drivers/infiniband/core/ucma.c in the Linux kernel through 4.17.11 allows ucma_leave_multicast to access a certain data structure after a cleanup ste…

Fix: after 4.17.11
Fix from $1,950 2018-07-29
Linux Kernel MEDIUM 5.5
CVE-2018-14611

An issue was discovered in the Linux kernel through 4.17.10. There is a use-after-free in try_merge_free_space() when mounting a crafted btrfs image,…

Fix: after 4.17.10
Fix from $1,600 2018-07-27
Linux Kernel MEDIUM 5.5
CVE-2018-10876

A flaw was found in Linux kernel in the ext4 filesystem code. A use-after-free is possible in ext4_ext_remove_space() function when mounting and oper…

Patch available
Fix from $1,600 2018-07-26
Linux Kernel HIGH 7.0
CVE-2018-5873

An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a U…

Fix: 4.1.50 / 4.4.116+
Fix from $1,950 2018-07-06
Linux Kernel MEDIUM 5.5
CVE-2018-12929

ntfs_read_locked_inode in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a use-after-free read and possibly cau…

Mitigation only
Fix from $1,600 2018-06-28
Linux Kernel MEDIUM 5.9
CVE-2018-11412EPSS 16%

In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain cir…

Fix: after 4.16.11
Fix from $1,600 2018-05-24
Linux Kernel HIGH 7.8
CVE-2018-10675

The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or…

Fix: 3.2.95 / 3.16.50+
Fix from $1,950 2018-05-02
Linux Kernel HIGH 7.8
CVE-2017-18218

In drivers/net/ethernet/hisilicon/hns/hns_enet.c in the Linux kernel before 4.13, local users can cause a denial of service (use-after-free and BUG) …

Fix: 4.9.92 / 4.13+
Fix from $1,950 2018-03-05
Linux Kernel HIGH 7.0
CVE-2017-18202

The __oom_reap_task_mm function in mm/oom_kill.c in the Linux kernel before 4.14.4 mishandles gather operations, which allows attackers to cause a de…

Fix: 4.9.68 / 4.14.4+
Fix from $1,950 2018-02-27
Linux Kernel HIGH 8.1
CVE-2017-15126

A use-after-free flaw was found in fs/userfaultfd.c in the Linux kernel before 4.13.6. The issue is related to the handling of fork failure when deal…

Fix: 4.13.6+
Fix from $1,950 2018-01-14
Linux Kernel HIGH 7.8
CVE-2018-5344

In the Linux kernel through 4.14.13, drivers/block/loop.c mishandles lo_release serialization, which allows attackers to cause a denial of service (_…

Fix: after 4.14.13
Fix from $1,950 2018-01-12
Linux Kernel CRITICAL 9.8
CVE-2017-18017EPSS 53%

The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to c…

Fix: 3.2.99 / 3.10.108+
Fix from $2,300 2018-01-03
Linux Kernel MEDIUM 5.5
CVE-2017-17975

Use-after-free in the usbtv_probe function in drivers/media/usb/usbtv/usbtv-core.c in the Linux kernel through 4.14.10 allows attackers to cause a de…

Fix: after 4.14.10
Fix from $1,600 2017-12-30
Linux Kernel HIGH 7.8
CVE-2017-8824

The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of servic…

Fix: 3.2.97 / 3.16.52+
Fix from $1,950 2017-12-05
Linux Kernel HIGH 7.8
CVE-2017-17052

The mm_init function in kernel/fork.c in the Linux kernel before 4.12.10 does not clear the ->exe_file member of a new process's mm_struct, allowing …

Fix: 4.9.46 / 4.12.10+
Fix from $1,950 2017-11-29
Linux Kernel HIGH 7.0
CVE-2017-17053

The init_new_context function in arch/x86/include/asm/mmu_context.h in the Linux kernel before 4.12.10 does not correctly handle errors from LDT tabl…

Fix: 4.4.153 / 4.9.46+
Fix from $1,950 2017-11-29
Linux Kernel HIGH 7.8
CVE-2017-16939

The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denia…

Fix: 3.2.97 / 3.16.52+
Fix from $1,950 2017-11-24
Linux Kernel HIGH 7.8
CVE-2017-15115

The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off act…

Fix: 3.2.96 / 3.16.51+
Fix from $1,950 2017-11-15
Linux Kernel MEDIUM 6.6
CVE-2017-16648

The dvb_frontend_free function in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel through 4.13.11 allows local users to cause a denial of s…

Fix: after 4.13.11
Fix from $1,600 2017-11-07
Linux Kernel MEDIUM 6.6
CVE-2017-16525

The usb_serial_console_disconnect function in drivers/usb/serial/console.c in the Linux kernel before 4.13.8 allows local users to cause a denial of …

Fix: 3.2.96 / 3.10.108+
Fix from $1,600 2017-11-04
Linux Kernel MEDIUM 6.6
CVE-2017-16527

sound/usb/mixer.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (snd_usb_mixer_interrupt use-after-free and syste…

Fix: 3.2.95 / 3.16.50+
Fix from $1,600 2017-11-04
Linux Kernel MEDIUM 6.6
CVE-2017-16528

sound/core/seq_device.c in the Linux kernel before 4.13.4 allows local users to cause a denial of service (snd_rawmidi_dev_seq_free use-after-free an…

Fix: 4.1.47 / 4.4.99+
Fix from $1,600 2017-11-04