Vulnerability index

Browse CVEs

602 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Linux Kernel MEDIUM 6.7
CVE-2018-1068

A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privileged user to arbitrarily wri…

Fix: 3.2.102 / 3.16.57+
Fix from $1,600 2018-03-16
Linux Kernel CRITICAL 9.8
CVE-2018-5703

The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.14.11 allows attackers to cause a denial of service (slab out-…

Fix: 4.14.86 / 4.15.8+
Fix from $2,300 2018-01-16
Linux Kernel HIGH 7.8
CVE-2018-5332

In the Linux kernel through 3.2, the rds_message_alloc_sgs() function does not validate a value that is used during DMA page allocation, leading to a…

Fix: 3.2.99 / 3.16.54+
Fix from $1,950 2018-01-11
Linux Kernel HIGH 7.8
CVE-2017-17806

The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkey…

Fix: 3.2.97 / 3.16.52+
Fix from $1,950 2017-12-20
Linux Kernel MEDIUM 6.6
CVE-2017-17558

The usb_destroy_configuration function in drivers/usb/core/config.c in the USB core subsystem in the Linux kernel through 4.14.5 does not consider th…

Fix: after 4.14.5
Fix from $1,600 2017-12-12
Linux Kernel MEDIUM 5.5
CVE-2017-1000255

On Linux running on PowerPC hardware (Power8 or later) a user process can craft a signal frame and then do a sigreturn so that the kernel will take a…

Mitigation only
Fix from $1,600 2017-10-30
Linux Kernel HIGH 7.8
CVE-2017-1000111

Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket opt…

Fix: 3.2.92 / 3.10.108+
Fix from $1,950 2017-10-05
Linux Kernel HIGH 8.0
CVE-2017-1000251EPSS 16%

The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to…

Fix: 3.2.94 / 3.16.49+
Fix from $1,950 2017-09-12
Linux Kernel HIGH 7.8
CVE-2017-1000363

Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and the fact that parport_ptr integer is static, a 'secure boot' kernel c…

Fix: 3.2.91 / 3.10.106+
Fix from $1,950 2017-07-17
Linux Kernel HIGH 7.0
CVE-2017-0608

An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the …

Patch available
Fix from $1,950 2017-05-12
Linux Kernel HIGH 7.8
CVE-2017-8067

drivers/char/virtio_console.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK option, which allo…

Fix: 4.9.24 / 4.10.12+
Fix from $1,950 2017-04-23
Linux Kernel CRITICAL 9.8
CVE-2017-0561EPSS 30%

A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of t…

Patch available
Fix from $2,300 2017-04-07
Linux Kernel HIGH 7.0
CVE-2017-0325

An elevation of privilege vulnerability in the NVIDIA I2C HID driver could enable a local malicious application to execute arbitrary code within the …

Patch available
Fix from $1,950 2017-04-05
Linux Kernel HIGH 7.0
CVE-2017-0332

An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execute arbitrary code within the c…

Patch available
Fix from $1,950 2017-04-05
Linux Kernel HIGH 7.8
CVE-2017-7308EPSS 18%

The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which a…

Fix: 3.2.89 / 3.10.107+
Fix from $1,950 2017-03-29
Linux Kernel HIGH 7.8
CVE-2017-7294

The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.6 does not validate addition of cer…

Fix: 3.2.89 / 3.10.107+
Fix from $1,950 2017-03-29
Linux Kernel HIGH 7.0
CVE-2017-0453

An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the …

Patch available
Fix from $1,950 2017-03-08
Linux Kernel HIGH 7.8
CVE-2017-0429

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the cont…

Fix: after 7.1.1
Fix from $1,950 2017-02-08
Linux Kernel HIGH 7.8
CVE-2016-9755

The netfilter subsystem in the Linux kernel before 4.9 mishandles IPv6 reassembly, which allows local users to cause a denial of service (integer ove…

Fix: after 4.8.15
Fix from $1,950 2016-12-28
Linux Kernel HIGH 7.8
CVE-2016-5342

Heap-based buffer overflow in the wcnss_wlan_write function in drivers/net/wireless/wcnss/wcnss_wlan.c in the wcnss_wlan device driver for the Linux …

Fix: after 7.0
Fix from $1,950 2016-08-30
Linux Kernel HIGH 7.8
CVE-2016-2065

sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) …

Fix: after 3.19.8
Fix from $1,950 2016-08-07
Linux Kernel HIGH 7.8
CVE-2015-0570

Stack-based buffer overflow in the SET_WPS_IE IOCTL implementation in wlan_hdd_hostapd.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and …

Fix: after 4.20.15
Fix from $1,950 2016-05-09
Linux Kernel HIGH 7.8
CVE-2015-0569EPSS 6%

Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka Wi-Fi) driver for the Linux ke…

Fix: after 4.20.15
Fix from $1,950 2016-05-09
Linux Kernel HIGH 7.2
CVE-2014-4322

drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM dev…

Fix: after 3.18.1
Fix from $1,950 2014-12-24
Linux Kernel MEDIUM 5.5
CVE-2014-0077

drivers/vhost/net.c in the Linux kernel before 3.13.10, when mergeable buffers are disabled, does not properly validate packet lengths, which allows …

Fix: 3.13.10+
Fix from $1,600 2014-04-14
Linux Kernel CRITICAL 9.8
CVE-2011-1180

Multiple stack-based buffer overflows in the iriap_getvaluebyclass_indication function in net/irda/iriap.c in the Linux kernel before 2.6.39 allow re…

Fix: 2.6.39+
Fix from $2,300 2013-06-08
Linux Kernel HIGH 7.6
CVE-2012-3400EPSS 9%

Heap-based buffer overflow in the udf_load_logicalvol function in fs/udf/super.c in the Linux kernel before 3.4.5 allows remote attackers to cause a …

Fix: 3.0.37 / 3.2.23+
Fix from $1,950 2012-10-03
Linux Kernel HIGH 7.8
CVE-2010-4656

The iowarrior_write function in drivers/usb/misc/iowarrior.c in the Linux kernel before 2.6.37 does not properly allocate memory, which might allow l…

Fix: 2.6.37+
Fix from $1,950 2011-07-18
Linux Kernel HIGH 7.2
CVE-2011-1013

Integer signedness error in the drm_modeset_ctl function in (1) drivers/gpu/drm/drm_irq.c in the Direct Rendering Manager (DRM) subsystem in the Linu…

Fix: 2.6.38+
Fix from $1,950 2011-05-09
Linux Kernel HIGH 7.2
CVE-2011-1017

Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2.6.37.2 and earlier might allow local users to ga…

Fix: 2.6.37.2+
Fix from $1,950 2011-03-01