CVE-2014-9428
- EPSS 2.95%
- Veröffentlicht 02.01.2015 21:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The batadv_frag_merge_packets function in net/batman-adv/fragmentation.c in the B.A.T.M.A.N. implementation in the Linux kernel through 3.18.1 uses an incorrect length field during a calculation of an amount of memory, which allows remote attackers t...
CVE-2014-9420
- EPSS 0.08%
- Veröffentlicht 26.12.2014 00:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The rock_continue function in fs/isofs/rock.c in the Linux kernel through 3.18.1 does not restrict the number of Rock Ridge continuation entries, which allows local users to cause a denial of service (infinite loop, and system crash or hang) via a cr...
CVE-2014-9419
- EPSS 0.06%
- Veröffentlicht 26.12.2014 00:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel through 3.18.1 does not ensure that Thread Local Storage (TLS) descriptors are loaded before proceeding with other steps, which makes it easier for local users to bypass the...
CVE-2014-4322
- EPSS 3.45%
- Veröffentlicht 24.12.2014 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate certain offset, length, and base values within an ioctl ca...
CVE-2014-9322
- EPSS 5.76%
- Veröffentlicht 17.12.2014 11:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access t...
CVE-2014-8133
- EPSS 0.04%
- Veröffentlicht 17.12.2014 11:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
arch/x86/kernel/tls.c in the Thread Local Storage (TLS) implementation in the Linux kernel through 3.18.1 allows local users to bypass the espfix protection mechanism, and consequently makes it easier for local users to bypass the ASLR protection mec...
CVE-2014-8134
- EPSS 0.08%
- Veröffentlicht 12.12.2014 18:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted ...
CVE-2014-4323
- EPSS 1.66%
- Veröffentlicht 12.12.2014 11:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mdp_lut_hw_update function in drivers/video/msm/mdp.c in the MDP display driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate certain start and l...
CVE-2014-9090
- EPSS 0.04%
- Veröffentlicht 30.11.2014 01:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The do_double_fault function in arch/x86/kernel/traps.c in the Linux kernel through 3.17.4 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to cause a denial of service (panic) via a mo...
CVE-2014-8989
- EPSS 0.03%
- Veröffentlicht 30.11.2014 01:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by leveraging a POSIX ACL containing an entry for the g...