CVE-2015-8970
- EPSS 0.04%
- Veröffentlicht 28.11.2016 03:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed, which allows local users to cause a denial of service (NULL pointer der...
CVE-2015-1328
- EPSS 89.38%
- Veröffentlicht 28.11.2016 03:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access b...
CVE-2016-7916
- EPSS 0.05%
- Veröffentlicht 16.11.2016 05:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in the environ_read function in fs/proc/base.c in the Linux kernel before 4.5.4 allows local users to obtain sensitive information from kernel memory by reading a /proc/*/environ file during a process-setup time interval in which envir...
- EPSS 0.16%
- Veröffentlicht 16.11.2016 05:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
The nfnetlink_rcv_batch function in net/netfilter/nfnetlink.c in the Linux kernel before 4.5 does not check whether a batch message's length field is large enough, which allows local users to obtain sensitive information from kernel memory or cause a...
CVE-2016-7915
- EPSS 0.29%
- Veröffentlicht 16.11.2016 05:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) by connecting a device, a...
CVE-2016-7913
- EPSS 0.54%
- Veröffentlicht 16.11.2016 05:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xc2028_set_config function in drivers/media/tuners/tuner-xc2028.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) via vectors involving omission of the firmware name from a certai...
CVE-2016-7914
- EPSS 0.18%
- Veröffentlicht 16.11.2016 05:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows local users to obtain sensitive information from kernel memory or cause a denial of service...
CVE-2016-7912
- EPSS 0.27%
- Veröffentlicht 16.11.2016 05:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the ffs_user_copy_worker function in drivers/usb/gadget/function/f_fs.c in the Linux kernel before 4.5.3 allows local users to gain privileges by accessing an I/O data structure after a certain callback call.
CVE-2016-7911
- EPSS 0.19%
- Veröffentlicht 16.11.2016 05:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in the get_task_ioprio function in block/ioprio.c in the Linux kernel before 4.6.6 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted ioprio_get system call.
CVE-2016-7910
- EPSS 0.26%
- Veröffentlicht 16.11.2016 05:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the disk_seqf_stop function in block/genhd.c in the Linux kernel before 4.7.1 allows local users to gain privileges by leveraging the execution of a certain stop operation even if the corresponding start operation had ...