- EPSS 0.08%
- Veröffentlicht 09.09.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:39
A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b...
CVE-2020-1749
- EPSS 0.16%
- Veröffentlicht 09.09.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 05:11:18
A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encrypted tunnel is created between two hosts, the kernel isn't correctly routing tunneled data over the ...
CVE-2020-3702
- EPSS 0.3%
- Veröffentlicht 08.09.2020 10:15:16
- Zuletzt bearbeitet 21.11.2024 05:31:36
u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic' in Snapdragon A...
CVE-2020-10720
- EPSS 0.13%
- Veröffentlicht 03.09.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:55
A flaw was found in the Linux kernel's implementation of GRO in versions before 5.2. This flaw allows an attacker with local access to crash the system.
CVE-2020-14356
- EPSS 0.82%
- Veröffentlicht 19.08.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:03:05
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
CVE-2020-24394
- EPSS 0.05%
- Veröffentlicht 19.08.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 05:14:44
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current umask is not considered.
CVE-2020-16166
- EPSS 1.68%
- Veröffentlicht 30.07.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:06:53
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c...
CVE-2020-15852
- EPSS 0.16%
- Veröffentlicht 20.07.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:06:18
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes ...
CVE-2020-0305
- EPSS 0.04%
- Veröffentlicht 17.07.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:53:16
In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:...
CVE-2020-15780
- EPSS 0.7%
- Veröffentlicht 15.07.2020 22:15:14
- Zuletzt bearbeitet 21.11.2024 05:06:09
An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be used by attackers to bypass lockdown and secure boot restrictions, aka CID-75b0cea7bf30.