CVE-2019-14816
- EPSS 0.23%
- Veröffentlicht 20.09.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:27:25
There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
CVE-2019-6454
- EPSS 0.11%
- Veröffentlicht 21.03.2019 16:01:08
- Zuletzt bearbeitet 21.11.2024 04:46:28
An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can expl...
CVE-2018-16866
- EPSS 0.11%
- Veröffentlicht 11.01.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:28
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.
CVE-2017-15129
- EPSS 0.07%
- Veröffentlicht 09.01.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:07
A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in ne...
CVE-2015-4170
- EPSS 0.06%
- Veröffentlicht 02.05.2016 10:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial of service (ldsem_down_read and ldsem_down_write deadlock) by establishing a new tty thread...
CVE-2015-3214
- EPSS 1.47%
- Veröffentlicht 31.08.2015 10:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an inva...
CVE-2015-5165
- EPSS 10.86%
- Veröffentlicht 12.08.2015 14:59:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.