CVE-2014-9585
- EPSS 0.05%
- Veröffentlicht 09.01.2015 21:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the ...
CVE-2014-9584
- EPSS 0.13%
- Veröffentlicht 09.01.2015 21:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel...
CVE-2014-9322
- EPSS 5.76%
- Veröffentlicht 17.12.2014 11:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access t...
- EPSS 1.73%
- Veröffentlicht 16.12.2014 18:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.
CVE-2014-8134
- EPSS 0.08%
- Veröffentlicht 12.12.2014 18:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted ...
CVE-2014-8559
- EPSS 0.06%
- Veröffentlicht 10.11.2014 11:55:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application.
CVE-2014-8369
- EPSS 0.08%
- Veröffentlicht 10.11.2014 11:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or p...
CVE-2014-7826
- EPSS 0.08%
- Veröffentlicht 10.11.2014 11:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem, which allows local users to gain privileges or cause a denial of service (invalid pointer dereferenc...
CVE-2014-3690
- EPSS 0.01%
- Veröffentlicht 10.11.2014 11:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or caus...
CVE-2014-3647
- EPSS 0.03%
- Veröffentlicht 10.11.2014 11:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.