CVE-2014-8559
- EPSS 0.06%
- Published 10.11.2014 11:55:09
- Last modified 12.04.2025 10:46:40
The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application.
CVE-2014-8369
- EPSS 0.08%
- Published 10.11.2014 11:55:08
- Last modified 12.04.2025 10:46:40
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or p...
CVE-2014-3690
- EPSS 0.01%
- Published 10.11.2014 11:55:07
- Last modified 12.04.2025 10:46:40
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or caus...
CVE-2014-3687
- EPSS 1.98%
- Published 10.11.2014 11:55:06
- Last modified 12.04.2025 10:46:40
The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork ...
CVE-2014-5077
- EPSS 14.7%
- Published 01.08.2014 11:13:09
- Last modified 12.04.2025 10:46:40
The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by starting to establish an assoc...
- EPSS 14.14%
- Published 03.07.2014 04:22:16
- Last modified 12.04.2025 10:46:40
The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.
CVE-2014-4608
- EPSS 8.66%
- Published 03.07.2014 04:22:15
- Last modified 12.04.2025 10:46:40
Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service (memory corruption) via a cra...
CVE-2014-4027
- EPSS 0.09%
- Published 23.06.2014 11:21:18
- Last modified 12.04.2025 10:46:40
The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveragin...
CVE-2014-3153
- EPSS 79.92%
- Published 07.06.2014 14:55:27
- Last modified 12.04.2025 10:46:40
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe wai...
CVE-2014-1738
- EPSS 0.03%
- Published 11.05.2014 21:55:05
- Last modified 12.04.2025 10:46:40
The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from...