CVE-2017-0648
- EPSS 1.85%
- Veröffentlicht 14.06.2017 13:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High due to the possibility of a local permanent device c...
CVE-2017-0650
- EPSS 0.74%
- Veröffentlicht 14.06.2017 13:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An information disclosure vulnerability in the Synaptics touchscreen driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Low because it first requires compromising a privileged pro...
CVE-2017-0651
- EPSS 1%
- Veröffentlicht 14.06.2017 13:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An information disclosure vulnerability in the kernel ION subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Low because it first requires compromising a privileged process. Pr...
CVE-2017-9605
- EPSS 0.38%
- Veröffentlicht 13.06.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The vmw_gb_surface_define_ioctl function (accessible via DRM_IOCTL_VMW_GB_SURFACE_CREATE) in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.11.4 defines a backup_handle variable but does not give it an initial value. If one att...
CVE-2017-9242
- EPSS 0.41%
- Veröffentlicht 27.05.2017 01:29:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel through 4.11.3 is too late in checking whether an overwrite of an skb data structure may occur, which allows local users to cause a denial of service (system crash) via craft...
CVE-2017-9211
- EPSS 0.39%
- Veröffentlicht 23.05.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey function that lacks a key-size check, which allows local users to cause a denial of service (NULL pointer dereference) via a crafted appl...
CVE-2017-9150
- EPSS 1.26%
- Veröffentlicht 22.05.2017 22:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value available for restricting the output of the print_bpf_insn function, which allows local users to obtain sensitive address informa...
CVE-2017-9077
- EPSS 0.72%
- Veröffentlicht 19.05.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related is...
CVE-2017-9074
- EPSS 0.42%
- Veröffentlicht 19.05.2017 07:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid option, which allows local users to cause a denial of service (out-of-bounds read and BUG) or possibly...
CVE-2017-9075
- EPSS 0.37%
- Veröffentlicht 19.05.2017 07:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related is...