Vulnerability index

Browse CVEs

2,191 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Linux Kernel MEDIUM 5.5
CVE-2017-12193

The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.13.11 mishandles node splitting, which allows lo…

Fix: 4.13.11+
Fix from $1,600 2017-11-22
Linux Kernel MEDIUM 6.3
CVE-2017-15102

The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for ins…

Fix: 4.8.1+
Fix from $1,600 2017-11-15
Linux Kernel MEDIUM 6.6
CVE-2017-16646

drivers/media/usb/dvb-usb/dib0700_devices.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (BUG and system crash…

Fix: after 4.13.11
Fix from $1,600 2017-11-07
Linux Kernel MEDIUM 6.6
CVE-2017-16647

drivers/net/usb/asix_devices.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and syst…

Fix: after 4.13.11
Fix from $1,600 2017-11-07
Linux Kernel MEDIUM 5.5
CVE-2017-15306

The kvm_vm_ioctl_check_extension function in arch/powerpc/kvm/powerpc.c in the Linux kernel before 4.13.11 allows local users to cause a denial of se…

Fix: after 4.13.10
Fix from $1,600 2017-11-06
Linux Kernel MEDIUM 6.6
CVE-2017-16532

The get_endpoints function in drivers/usb/misc/usbtest.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL po…

Fix: 3.2.95 / 3.16.50+
Fix from $1,600 2017-11-04
Linux Kernel MEDIUM 6.6
CVE-2017-16536

The cx231xx_usb_probe function in drivers/media/usb/cx231xx/cx231xx-cards.c in the Linux kernel through 4.13.11 allows local users to cause a denial …

Fix: after 4.13.11
Fix from $1,600 2017-11-04
Linux Kernel MEDIUM 6.6
CVE-2017-16537

The imon_probe function in drivers/media/rc/imon.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer …

Fix: after 4.13.7
Fix from $1,600 2017-11-04
Linux Kernel MEDIUM 5.5
CVE-2017-15299

The KEYS subsystem in the Linux kernel through 4.13.7 mishandles use of add_key for a key that already exists but is uninstantiated, which allows loc…

Fix: after 4.13.6
Fix from $1,600 2017-10-14
Linux Kernel MEDIUM 5.5
CVE-2017-12192

The keyctl_read_key function in security/keys/keyctl.c in the Key Management subcomponent in the Linux kernel before 4.13.5 does not properly conside…

Fix: after 4.13.4
Fix from $1,600 2017-10-12
Linux Kernel MEDIUM 5.5
CVE-2017-15274

security/keys/keyctl.c in the Linux kernel before 4.11.5 does not consider the case of a NULL payload in conjunction with a nonzero length value, whi…

Fix: after 4.11.4
Fix from $1,600 2017-10-12
Linux Kernel MEDIUM 5.5
CVE-2017-14340

The XFS_IS_REALTIME_INODE macro in fs/xfs/xfs_linux.h in the Linux kernel before 4.13.2 does not verify that a filesystem has a realtime device, whic…

Fix: after 4.13.1
Fix from $1,600 2017-09-15
Linux Kernel HIGH 7.8
CVE-2017-13686

net/ipv4/route.c in the Linux kernel 4.13-rc1 through 4.13-rc6 is too late to check for a NULL fi field when RTM_F_FIB_MATCH is set, which allows loc…

Patch available
Fix from $1,950 2017-08-24
Linux Kernel MEDIUM 5.5
CVE-2017-9211

The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey function that lacks a key-size check…

Fix: after 4.11.2
Fix from $1,600 2017-05-23
Linux Kernel MEDIUM 5.5
CVE-2017-8106

The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12 through 3.15 allows privileged KVM guest OS users to cause a denial of serv…

Mitigation only
Fix from $1,600 2017-04-24
Linux Kernel HIGH 7.8
CVE-2016-5870

The msm_ipc_router_close function in net/ipc_router/ipc_router_socket.c in the ipc_router component for the Linux kernel 3.x, as used in Qualcomm Inn…

Fix: after 3.19.8
Fix from $1,950 2017-04-04
Linux Kernel HIGH 7.8
CVE-2017-7374

Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereferenc…

Fix: 4.4.59 / 4.9.20+
Fix from $1,950 2017-03-31
Linux Kernel HIGH 7.8
CVE-2017-2647

The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and s…

Fix: after 3.17.8
Fix from $1,950 2017-03-31
Linux Kernel MEDIUM 5.5
CVE-2017-6951

The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL …

Fix: after 3.14.79
Fix from $1,600 2017-03-16
Linux Kernel HIGH 7.5
CVE-2017-5970

The ipv4_pktinfo_prepare function in net/ipv4/ip_sockglue.c in the Linux kernel through 4.9.9 allows attackers to cause a denial of service (system c…

Fix: after 4.9.9
Fix from $1,950 2017-02-14
Linux Kernel MEDIUM 5.5
CVE-2016-10147

crypto/mcryptd.c in the Linux kernel before 4.8.15 allows local users to cause a denial of service (NULL pointer dereference and system crash) by usi…

Fix: after 4.8.14
Fix from $1,600 2017-01-18
Linux Kernel HIGH 7.8
CVE-2016-9313

security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registra…

Fix: 4.8.7+
Fix from $1,950 2016-11-28
Linux Kernel MEDIUM 5.5
CVE-2016-8646

The hash_accept function in crypto/algif_hash.c in the Linux kernel before 4.3.6 allows local users to cause a denial of service (OOPS) by attempting…

Fix: after 4.3.5
Fix from $1,600 2016-11-28
Linux Kernel MEDIUM 5.5
CVE-2016-8630

The x86_decode_insn function in arch/x86/kvm/emulate.c in the Linux kernel before 4.8.7, when KVM is enabled, allows local users to cause a denial of…

Fix: after 4.8.6
Fix from $1,600 2016-11-28
Linux Kernel MEDIUM 5.5
CVE-2015-8970

crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an acc…

Fix: after 4.4.1
Fix from $1,600 2016-11-28
Linux Kernel MEDIUM 5.5
CVE-2016-7914

The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, whi…

Fix: after 4.5.2
Fix from $1,600 2016-11-16
Linux Kernel MEDIUM 5.5
CVE-2016-6327

drivers/infiniband/ulp/srpt/ib_srpt.c in the Linux kernel before 4.5.1 allows local users to cause a denial of service (NULL pointer dereference and …

Fix: after 4.5.0
Fix from $1,600 2016-10-16
Linux Kernel MEDIUM 6.1
CVE-2015-8956

The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in the Linux kernel before 4.2 allows local users to obtain sensitive information or cau…

Fix: after 7.0
Fix from $1,600 2016-10-10
Linux Kernel CRITICAL 9.8
CVE-2015-0573

drivers/media/platform/msm/broadcast/tsc.c in the TSC driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contribut…

Fix: after 3.19.8
Fix from $2,300 2016-08-07
Linux Kernel MEDIUM 6.0
CVE-2015-8551

The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrat…

Fix: after 4.3.6
Fix from $1,600 2016-04-13