CVE-2016-4569
- EPSS 0.84%
- Veröffentlicht 23.05.2016 10:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer...
CVE-2016-4568
- EPSS 0.36%
- Veröffentlicht 23.05.2016 10:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
drivers/media/v4l2-core/videobuf2-v4l2.c in the Linux kernel before 4.5.3 allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a crafted number of planes in a VIDIOC_DQBUF ioctl...
CVE-2016-4565
- EPSS 0.48%
- Veröffentlicht 23.05.2016 10:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI int...
- EPSS 0.87%
- Veröffentlicht 23.05.2016 10:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted application on (1) a system with more than ...
CVE-2016-4557
- EPSS 10.2%
- Veröffentlicht 23.05.2016 10:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly maintain an fd data structure, which allows local users to gain privileges or cause a denial of service (use-after-free) via crafted ...
CVE-2016-4486
- EPSS 1.71%
- Veröffentlicht 23.05.2016 10:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.
CVE-2016-4485
- EPSS 4.67%
- Veröffentlicht 23.05.2016 10:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.
CVE-2016-4482
- EPSS 0.55%
- Veröffentlicht 23.05.2016 10:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTIN...
CVE-2016-3951
- EPSS 0.59%
- Veröffentlicht 02.05.2016 10:59:41
- Zuletzt bearbeitet 06.05.2026 22:30:45
Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invali...
CVE-2016-3689
- EPSS 0.59%
- Veröffentlicht 02.05.2016 10:59:40
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device without both a master and a slave interface.