CVE-2015-2041
- EPSS 0.07%
- Veröffentlicht 21.04.2015 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a s...
CVE-2015-1465
- EPSS 7.72%
- Veröffentlicht 05.04.2015 21:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The IPv4 implementation in the Linux kernel before 3.18.8 does not properly consider the length of the Read-Copy Update (RCU) grace period for redirecting lookups in the absence of caching, which allows remote attackers to cause a denial of service (...
- EPSS 1.97%
- Veröffentlicht 16.03.2015 10:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The stack randomization feature in the Linux kernel before 3.19.1 on 64-bit platforms uses incorrect data types for the results of bitwise left-shift operations, which makes it easier for attackers to bypass the ASLR protection mechanism by predictin...
CVE-2015-1420
- EPSS 0.04%
- Veröffentlicht 16.03.2015 10:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of ...
- EPSS 13.93%
- Veröffentlicht 16.03.2015 10:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by tri...
CVE-2015-0274
- EPSS 0.05%
- Veröffentlicht 16.03.2015 10:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replacement, which allows local users to cause a denial of service (transaction overrun and data corruption) or possibly gain privileges ...
CVE-2014-8173
- EPSS 0.05%
- Veröffentlicht 16.03.2015 10:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable.h in the Linux kernel before 3.13 on NUMA systems does not properly determine whether a Page Middle Directory (PMD) entry is a transparent huge-table entry, which allows ...
CVE-2014-8172
- EPSS 0.1%
- Veröffentlicht 16.03.2015 10:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The filesystem implementation in the Linux kernel before 3.13 performs certain operations on lists of files with an inappropriate locking approach, which allows local users to cause a denial of service (soft lockup or system crash) via unspecified us...
CVE-2014-8159
- EPSS 0.08%
- Veröffentlicht 16.03.2015 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary p...
CVE-2014-7822
- EPSS 0.68%
- Veröffentlicht 16.03.2015 10:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restriction on the maximum size of a single file, which allows local users to cause a denial of service (system crash) or possibly have unsp...