CVE-2012-3511
- EPSS 0.09%
- Veröffentlicht 04.10.2012 03:28:35
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple race conditions in the madvise_remove function in mm/madvise.c in the Linux kernel before 3.4.5 allow local users to cause a denial of service (use-after-free and system crash) via vectors involving a (1) munmap or (2) close system call.
CVE-2012-3520
- EPSS 0.09%
- Veröffentlicht 03.10.2012 11:02:57
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Ava...
CVE-2012-3552
- EPSS 2.03%
- Veröffentlicht 03.10.2012 11:02:57
- Zuletzt bearbeitet 29.04.2026 01:13:23
Race condition in the IP implementation in the Linux kernel before 3.0 might allow remote attackers to cause a denial of service (slab corruption and system crash) by sending packets to an application that sets socket options during the handling of n...
CVE-2012-3375
- EPSS 0.14%
- Veröffentlicht 03.10.2012 11:02:56
- Zuletzt bearbeitet 29.04.2026 01:13:23
The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via ...
CVE-2012-3400
- EPSS 4.78%
- Veröffentlicht 03.10.2012 11:02:56
- Zuletzt bearbeitet 29.04.2026 01:13:23
Heap-based buffer overflow in the udf_load_logicalvol function in fs/udf/super.c in the Linux kernel before 3.4.5 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted UDF filesyst...
CVE-2012-3412
- EPSS 7%
- Veröffentlicht 03.10.2012 11:02:56
- Zuletzt bearbeitet 29.04.2026 01:13:23
The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 allows remote attackers to cause a denial of service (DMA descriptor consumption and network-controller outage) via crafted TCP packets that trigger a small MSS value.
CVE-2012-3430
- EPSS 0.18%
- Veröffentlicht 03.10.2012 11:02:56
- Zuletzt bearbeitet 29.04.2026 01:13:23
The rds_recvmsg function in net/rds/recv.c in the Linux kernel before 3.0.44 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) recvfrom or (2) recvm...
CVE-2012-3510
- EPSS 0.12%
- Veröffentlicht 03.10.2012 11:02:56
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in the Linux kernel before 2.6.19 allows local users to obtain potentially sensitive information from kernel memory or cause a denial of service (system crash) via a taskst...
CVE-2012-2745
- EPSS 0.13%
- Veröffentlicht 09.08.2012 10:29:47
- Zuletzt bearbeitet 29.04.2026 01:13:23
The copy_creds function in kernel/cred.c in the Linux kernel before 3.3.2 provides an invalid replacement session keyring to a child process, which allows local users to cause a denial of service (panic) via a crafted application that uses the fork s...
CVE-2012-2136
- EPSS 0.08%
- Veröffentlicht 09.08.2012 10:29:46
- Zuletzt bearbeitet 29.04.2026 01:13:23
The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local users to cause a denial of service (heap-based buffer overflow and system crash) or possibly g...