CVE-2014-6418
- EPSS 3.97%
- Veröffentlicht 28.09.2014 10:55:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from t...
CVE-2014-7145
- EPSS 1.21%
- Veröffentlicht 28.09.2014 10:55:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer dereference and client system crash) or possibly have unspecified other impact by deleting the IPC$ sh...
- EPSS 0.12%
- Veröffentlicht 01.09.2014 01:55:28
- Zuletzt bearbeitet 12.04.2025 10:46:40
Stack consumption vulnerability in the parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (uncontrolled recursion, and system crash or reboot) via a crafted i...
- EPSS 0.08%
- Veröffentlicht 01.09.2014 01:55:28
- Zuletzt bearbeitet 12.04.2025 10:46:40
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (unkillable mount process) via a crafted iso9660 image with a self-referential CL entry.
CVE-2014-3601
- EPSS 0.37%
- Veröffentlicht 01.09.2014 01:55:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruptio...
CVE-2014-5206
- EPSS 0.04%
- Veröffentlicht 18.08.2014 11:15:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
The do_remount function in fs/namespace.c in the Linux kernel through 3.16.1 does not maintain the MNT_LOCK_READONLY bit across a remount of a bind mount, which allows local users to bypass an intended read-only restriction and defeat certain sandbox...
CVE-2014-5207
- EPSS 0.23%
- Veröffentlicht 18.08.2014 11:15:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
fs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict clearing MNT_NODEV, MNT_NOSUID, and MNT_NOEXEC and changing MNT_ATIME_MASK during a remount of a bind mount, which allows local users to gain privileges, interfere with back...
CVE-2014-3534
- EPSS 0.07%
- Veröffentlicht 01.08.2014 11:13:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory lo...
CVE-2014-5045
- EPSS 0.03%
- Veröffentlicht 01.08.2014 11:13:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly maintain a certain reference count during attempts to use the umount system call in conjunction with a symlink, which allows local users to cause a denial ...
CVE-2014-5077
- EPSS 14.7%
- Veröffentlicht 01.08.2014 11:13:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by starting to establish an assoc...