Vulnerability index

Browse CVEs

2,191 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Linux Kernel CRITICAL 9.8
CVE-2015-8787EPSS 9%

The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of serv…

Fix: 4.1.31 / 4.4+
Fix from $2,300 2016-02-08
Linux Kernel HIGH 7.8
CVE-2014-7826

kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem,…

Fix: 3.2.65 / 3.4.106+
Fix from $1,950 2014-11-10
Linux Kernel HIGH 7.1
CVE-2014-5077EPSS 6%

The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attacke…

Fix: 3.2.63 / 3.4.103+
Fix from $1,950 2014-08-01
Linux Kernel HIGH 7.8
CVE-2014-0101EPSS 7%

The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable …

Fix: 3.2.56 / 3.4.84+
Fix from $1,950 2014-03-11
Linux Kernel HIGH 7.8
CVE-2013-1059

net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash…

Fix: 3.0.86 / 3.2.49+
Fix from $1,950 2013-07-08
Linux Kernel HIGH 7.5
CVE-2011-2482

A certain Red Hat patch to the sctp_sock_migrate function in net/sctp/socket.c in the Linux kernel before 2.6.21, as used in Red Hat Enterprise Linux…

Fix: 2.6.21+
Fix from $1,950 2013-06-08
Linux Kernel MEDIUM 5.5
CVE-2011-4081

crypto/ghash-generic.c in the Linux kernel before 3.1 allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly…

Fix: 3.1+
Fix from $1,600 2012-05-24
Linux Kernel HIGH 7.8
CVE-2012-1097

The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows l…

Fix: 3.0.24 / 3.2.10+
Fix from $1,950 2012-05-17
Linux Kernel MEDIUM 5.5
CVE-2012-1146

The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are…

Fix: 3.2.10+
Fix from $1,600 2012-05-17
Linux Kernel MEDIUM 5.5
CVE-2011-4594

The __sys_sendmsg function in net/socket.c in the Linux kernel before 3.1 allows local users to cause a denial of service (system crash) via crafted …

Fix: 3.1+
Fix from $1,600 2012-05-17
Linux Kernel MEDIUM 5.5
CVE-2011-3637

The m_stop function in fs/proc/task_mmu.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (OOPS) via vectors that t…

Fix: 2.6.39+
Fix from $1,600 2012-05-17
Linux Kernel HIGH 7.8
CVE-2011-2525

The qdisc_notify function in net/sched/sch_api.c in the Linux kernel before 2.6.35 does not prevent tc_fill_qdisc function calls referencing builtin …

Fix: 2.6.35+
Fix from $1,950 2012-02-02
Linux Kernel MEDIUM 5.7
CVE-2011-1478

The napi_reuse_skb function in net/core/dev.c in the Generic Receive Offload (GRO) implementation in the Linux kernel before 2.6.38 does not reset th…

Fix: 2.6.38+
Fix from $1,600 2011-10-23
Linux Kernel HIGH 7.8
CVE-2011-1771

The cifs_close function in fs/cifs/file.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (NULL pointer dereference…

Fix: 2.6.39+
Fix from $1,950 2011-09-06
Linux Kernel HIGH 7.2
CVE-2011-2184

The key_replace_session_keyring function in security/keys/process_keys.c in the Linux kernel before 2.6.39.1 does not initialize a certain structure …

Fix: 2.6.39.1+
Fix from $1,950 2011-09-06
Linux Kernel HIGH 7.8
CVE-2011-1093

The dccp_rcv_state_process function in net/dccp/input.c in the Datagram Congestion Control Protocol (DCCP) implementation in the Linux kernel before …

Fix: 2.6.38+
Fix from $1,950 2011-07-18
Linux Kernel HIGH 7.5
CVE-2011-0709

The br_mdb_ip_get function in net/bridge/br_multicast.c in the Linux kernel before 2.6.35-rc5 allows remote attackers to cause a denial of service (N…

Fix: after 2.6.34.7
Fix from $1,950 2011-02-18
Linux Kernel HIGH 7.9
CVE-2010-4263

The igb_receive_skb function in drivers/net/igb/igb_main.c in the Intel Gigabit Ethernet (aka igb) subsystem in the Linux kernel before 2.6.34, when …

Fix: 2.6.34+
Fix from $1,950 2011-01-18
Linux Kernel HIGH 7.1
CVE-2010-4342

The aun_incoming function in net/econet/af_econet.c in the Linux kernel before 2.6.37-rc6, when Econet is enabled, allows remote attackers to cause a…

Fix: 2.6.37+
Fix from $1,950 2010-12-30
Linux Kernel MEDIUM 6.6
CVE-2010-3437

Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users …

Fix: 2.6.36+
Fix from $1,600 2010-10-04
Linux Kernel MEDIUM 5.5
CVE-2010-3079

kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and…

Fix: 2.6.35.5+
Fix from $1,600 2010-09-30
Linux Kernel HIGH 7.8
CVE-2010-2960

The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyrin…

Fix: 2.6.35.4+
Fix from $1,950 2010-09-08
Linux Kernel HIGH 10.0
CVE-2010-2495

The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain …

Fix: 2.6.34+
Fix from $1,950 2010-09-08
Linux Kernel HIGH 7.8
CVE-2010-2798

The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with s…

Fix: 2.6.35+
Fix from $1,950 2010-09-08
Linux Kernel HIGH 7.1
CVE-2010-0006

The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.32.4, when network namespaces are enabled, allows remote attackers t…

Fix: 2.6.32.4+
Fix from $1,950 2010-01-26
Linux Kernel HIGH 7.0
CVE-2009-3547

Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference …

Fix: after 2.6.31.14
Fix from $1,950 2009-11-04
Linux Kernel HIGH 7.8
CVE-2009-3620

The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initializat…

Fix: 2.6.31.1+
Fix from $1,950 2009-10-22
Linux Kernel HIGH 7.8
CVE-2009-2698EPSS 7%

The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users …

Fix: 2.6.19+
Fix from $1,950 2009-08-27
Linux Kernel HIGH 7.8
CVE-2009-2768

The load_flat_shared_library function in fs/binfmt_flat.c in the flat subsystem in the Linux kernel before 2.6.31-rc6 allows local users to cause a d…

Fix: 2.6.31+
Fix from $1,950 2009-08-14
Linux Kernel HIGH 7.8
CVE-2008-2812

The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or p…

Fix: 2.6.25.10+
Fix from $1,950 2008-07-09