CVE-2017-15116
- EPSS 0.05%
- Veröffentlicht 30.11.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference).
CVE-2017-15102
- EPSS 0.11%
- Veröffentlicht 15.11.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occur...
CVE-2017-1000111
- EPSS 0.06%
- Veröffentlicht 05.10.2017 01:29:04
- Zuletzt bearbeitet 20.04.2025 01:37:25
Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_...
CVE-2017-1000253
- EPSS 54.19%
- Veröffentlicht 05.10.2017 01:29:04
- Zuletzt bearbeitet 22.10.2025 00:16:00
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4f...
CVE-2015-7837
- EPSS 0.07%
- Veröffentlicht 19.09.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secur...
CVE-2015-7553
- EPSS 0.04%
- Veröffentlicht 14.09.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Hat Enterprise MRG 2, when the nfnetlink_log module is loaded, allows local users to cause a denial of service (panic) by creating netlink sockets.
CVE-2017-10661
- EPSS 30%
- Veröffentlicht 19.08.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel q...
CVE-2017-3085
- EPSS 0.82%
- Veröffentlicht 11.08.2017 19:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
CVE-2017-3106
- EPSS 53.25%
- Veröffentlicht 11.08.2017 19:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution.
- EPSS 0.11%
- Veröffentlicht 10.08.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of service (crash) via a crafted catalog size in (1) the parallels_open function in block/parallels.c or (2) bochs_open function in bo...