CVE-2016-9084
- EPSS 0.38%
- Veröffentlicht 28.11.2016 03:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
drivers/vfio/pci/vfio_pci_intrs.c in the Linux kernel through 4.8.11 misuses the kzalloc function, which allows local users to cause a denial of service (integer overflow) or have unspecified other impact by leveraging access to a vfio PCI device fil...
CVE-2016-9083
- EPSS 0.38%
- Veröffentlicht 28.11.2016 03:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
drivers/vfio/pci/vfio_pci.c in the Linux kernel through 4.8.11 allows local users to bypass integer overflow checks, and cause a denial of service (memory corruption) or have unspecified other impact, by leveraging access to a vfio PCI device file fo...
CVE-2016-8650
- EPSS 0.41%
- Veröffentlicht 28.11.2016 03:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call...
CVE-2016-8646
- EPSS 0.43%
- Veröffentlicht 28.11.2016 03:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The hash_accept function in crypto/algif_hash.c in the Linux kernel before 4.3.6 allows local users to cause a denial of service (OOPS) by attempting to trigger use of in-kernel hash algorithms for a socket that has received zero bytes of data.
CVE-2016-8645
- EPSS 0.47%
- Veröffentlicht 28.11.2016 03:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The TCP stack in the Linux kernel before 4.8.10 mishandles skb truncation, which allows local users to cause a denial of service (system crash) via a crafted application that makes sendto system calls, related to net/ipv4/tcp_ipv4.c and net/ipv6/tcp_...
CVE-2016-8633
- EPSS 1.77%
- Veröffentlicht 28.11.2016 03:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
drivers/firewire/net.c in the Linux kernel before 4.8.7, in certain unusual hardware configurations, allows remote attackers to execute arbitrary code via crafted fragmented packets.
CVE-2016-8632
- EPSS 0.4%
- Veröffentlicht 28.11.2016 03:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The tipc_msg_build function in net/tipc/msg.c in the Linux kernel through 4.8.11 does not validate the relationship between the minimum fragment length and the maximum packet size, which allows local users to gain privileges or cause a denial of serv...
CVE-2016-8630
- EPSS 0.36%
- Veröffentlicht 28.11.2016 03:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The x86_decode_insn function in arch/x86/kvm/emulate.c in the Linux kernel before 4.8.7, when KVM is enabled, allows local users to cause a denial of service (host OS crash) via a certain use of a ModR/M byte in an undefined instruction.
CVE-2015-8970
- EPSS 0.5%
- Veröffentlicht 28.11.2016 03:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed, which allows local users to cause a denial of service (NULL pointer der...
CVE-2016-7916
- EPSS 0.39%
- Veröffentlicht 16.11.2016 05:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in the environ_read function in fs/proc/base.c in the Linux kernel before 4.5.4 allows local users to obtain sensitive information from kernel memory by reading a /proc/*/environ file during a process-setup time interval in which envir...