CVE-2019-9506
- EPSS 3.04%
- Veröffentlicht 14.08.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:51:45
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") tha...
CVE-2018-16871
- EPSS 1.53%
- Veröffentlicht 30.07.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 03:53:29
A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence....
CVE-2017-18344
- EPSS 11.3%
- Veröffentlicht 26.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:53
The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly validate the sigevent->sigev_notify field, which leads to out-of-bounds access in the show_timer function (called when /proc/$PID...
CVE-2018-13405
- EPSS 0.15%
- Veröffentlicht 06.07.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:47:02
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a memb...
CVE-2018-3639
- EPSS 44.99%
- Veröffentlicht 22.05.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 04:05:48
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access vi...
- EPSS 27.65%
- Veröffentlicht 03.01.2018 06:29:00
- Zuletzt bearbeitet 03.01.2025 12:15:25
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other im...
CVE-2014-7283
- EPSS 0.04%
- Veröffentlicht 13.10.2014 10:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementation in the Linux kernel before 3.14.2 does not properly compare btree hash values, which allows local users to cause a denial of service (filesystem corruption, and OOPS ...
- EPSS 3.44%
- Veröffentlicht 04.11.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathna...
CVE-2009-3620
- EPSS 0.07%
- Veröffentlicht 22.10.2009 16:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash...