CVE-2017-7979
- EPSS 0.4%
- Veröffentlicht 19.04.2017 23:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The cookie feature in the packet action API implementation in net/sched/act_api.c in the Linux kernel 4.11.x through 4.11-rc7 mishandles the tb nlattr array, which allows local users to cause a denial of service (uninitialized memory access and refco...
CVE-2017-7645
- EPSS 5.91%
- Veröffentlicht 18.04.2017 14:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a denial of service (system crash) via a long RPC reply, related to net/sunrpc/svc.c, fs/nfsd/nfs3xdr.c, and fs/nfsd/nfsxdr.c.
CVE-2017-7889
- EPSS 0.31%
- Veröffentlicht 17.04.2017 00:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to read or write to kernel memory locations in the first megabyte (and bypass slab-allocation access re...
CVE-2016-5856
- EPSS 0.59%
- Veröffentlicht 12.04.2017 22:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privileges, a different vulnerability than CVE-2016-5857.
CVE-2017-7616
- EPSS 0.41%
- Veröffentlicht 10.04.2017 14:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Incorrect error handling in the set_mempolicy and mbind compat syscalls in mm/mempolicy.c in the Linux kernel through 4.10.9 allows local users to obtain sensitive information from uninitialized stack data by triggering failure of a certain bitmap op...
CVE-2017-7618
- EPSS 4.26%
- Veröffentlicht 10.04.2017 14:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling its own callback, and infinite recursion) by triggering EBUSY on a full queue.
CVE-2017-0563
- EPSS 0.89%
- Veröffentlicht 07.04.2017 22:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent d...
CVE-2017-0564
- EPSS 4.25%
- Veröffentlicht 07.04.2017 22:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
An elevation of privilege vulnerability in the kernel ION subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent dev...
CVE-2017-0567
- EPSS 1.5%
- Veröffentlicht 07.04.2017 22:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privilege...
CVE-2017-0568
- EPSS 1.5%
- Veröffentlicht 07.04.2017 22:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privilege...