CVE-2017-15102
- EPSS 0.11%
- Published 15.11.2017 21:29:00
- Last modified 20.04.2025 01:37:25
The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occur...
CVE-2017-1000111
- EPSS 0.1%
- Published 05.10.2017 01:29:04
- Last modified 20.04.2025 01:37:25
Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_...
CVE-2017-1000253
- EPSS 55.57%
- Published 05.10.2017 01:29:04
- Last modified 20.04.2025 01:37:25
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4f...
CVE-2015-7837
- EPSS 0.07%
- Published 19.09.2017 16:29:00
- Last modified 20.04.2025 01:37:25
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secur...
CVE-2015-7553
- EPSS 0.04%
- Published 14.09.2017 16:29:00
- Last modified 20.04.2025 01:37:25
Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Hat Enterprise MRG 2, when the nfnetlink_log module is loaded, allows local users to cause a denial of service (panic) by creating netlink sockets.
CVE-2017-10661
- EPSS 27.64%
- Published 19.08.2017 18:29:00
- Last modified 20.04.2025 01:37:25
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel q...
CVE-2017-3085
- EPSS 0.82%
- Published 11.08.2017 19:29:02
- Last modified 20.04.2025 01:37:25
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
CVE-2017-3106
- EPSS 64.59%
- Published 11.08.2017 19:29:02
- Last modified 20.04.2025 01:37:25
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution.
- EPSS 0.09%
- Published 10.08.2017 15:29:00
- Last modified 20.04.2025 01:37:25
Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of service (crash) via a crafted catalog size in (1) the parallels_open function in block/parallels.c or (2) bochs_open function in bo...
CVE-2016-6312
- EPSS 0.52%
- Published 17.07.2017 13:18:06
- Last modified 20.04.2025 01:37:25
The mod_dontdothat component of the mod_dav_svn Apache module in Subversion as packaged in Red Hat Enterprise Linux 5.11 does not properly detect recursion during entity expansion, which allows remote authenticated users with access to the webdav rep...