CVE-2012-2669
- EPSS 0.08%
- Veröffentlicht 27.12.2012 11:47:00
- Zuletzt bearbeitet 29.04.2026 01:13:23
The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message.
- EPSS 1.26%
- Veröffentlicht 21.12.2012 11:47:36
- Zuletzt bearbeitet 29.04.2026 01:13:23
The ip6_frag_queue function in net/ipv6/reassembly.c in the Linux kernel before 2.6.36 allows remote attackers to bypass intended network restrictions via overlapping IPv6 fragments.
CVE-2012-4508
- EPSS 0.08%
- Veröffentlicht 21.12.2012 11:47:36
- Zuletzt bearbeitet 29.04.2026 01:13:23
Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from a deleted file by reading an extent that was not properly marked as uninitialized.
CVE-2012-4565
- EPSS 0.06%
- Veröffentlicht 21.12.2012 11:47:36
- Zuletzt bearbeitet 29.04.2026 01:13:23
The tcp_illinois_info function in net/ipv4/tcp_illinois.c in the Linux kernel before 3.4.19, when the net.ipv4.tcp_congestion_control illinois setting is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) by read...
- EPSS 0.06%
- Veröffentlicht 21.12.2012 11:47:36
- Zuletzt bearbeitet 29.04.2026 01:13:23
The online_pages function in mm/memory_hotplug.c in the Linux kernel before 3.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact in opportunistic circumstances by us...
CVE-2012-0957
- EPSS 0.5%
- Veröffentlicht 21.12.2012 11:47:35
- Zuletzt bearbeitet 29.04.2026 01:13:23
The override_release function in kernel/sys.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from kernel stack memory via a uname system call in conjunction with a UNAME26 personality.
CVE-2012-3511
- EPSS 0.09%
- Veröffentlicht 04.10.2012 03:28:35
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple race conditions in the madvise_remove function in mm/madvise.c in the Linux kernel before 3.4.5 allow local users to cause a denial of service (use-after-free and system crash) via vectors involving a (1) munmap or (2) close system call.
CVE-2012-3520
- EPSS 0.09%
- Veröffentlicht 03.10.2012 11:02:57
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Ava...
CVE-2012-3552
- EPSS 2.03%
- Veröffentlicht 03.10.2012 11:02:57
- Zuletzt bearbeitet 29.04.2026 01:13:23
Race condition in the IP implementation in the Linux kernel before 3.0 might allow remote attackers to cause a denial of service (slab corruption and system crash) by sending packets to an application that sets socket options during the handling of n...
CVE-2012-3375
- EPSS 0.14%
- Veröffentlicht 03.10.2012 11:02:56
- Zuletzt bearbeitet 29.04.2026 01:13:23
The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via ...