CVE-2016-3137
- EPSS 0.02%
- Veröffentlicht 02.05.2016 10:59:36
- Zuletzt bearbeitet 06.05.2026 22:30:45
drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both an interrupt-in and an interrupt-out endpoin...
CVE-2016-3136
- EPSS 0.2%
- Veröffentlicht 02.05.2016 10:59:35
- Zuletzt bearbeitet 06.05.2026 22:30:45
The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device without two i...
CVE-2016-2188
- EPSS 0.23%
- Veröffentlicht 02.05.2016 10:59:32
- Zuletzt bearbeitet 06.05.2026 22:30:45
The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device...
CVE-2016-2187
- EPSS 0.04%
- Veröffentlicht 02.05.2016 10:59:30
- Zuletzt bearbeitet 06.05.2026 22:30:45
The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device desc...
CVE-2016-2186
- EPSS 0.08%
- Veröffentlicht 02.05.2016 10:59:29
- Zuletzt bearbeitet 06.05.2026 22:30:45
The powermate_probe function in drivers/input/misc/powermate.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB devi...
CVE-2016-2185
- EPSS 0.06%
- Veröffentlicht 02.05.2016 10:59:28
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ati_remote2_probe function in drivers/input/misc/ati_remote2.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB ...
CVE-2015-1350
- EPSS 0.07%
- Veröffentlicht 02.05.2016 10:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a...
CVE-2016-3672
- EPSS 0.03%
- Veröffentlicht 27.04.2016 17:59:27
- Zuletzt bearbeitet 06.05.2026 22:30:45
The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, a...
CVE-2016-3134
- EPSS 0.04%
- Veröffentlicht 27.04.2016 17:59:22
- Zuletzt bearbeitet 06.05.2026 22:30:45
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
CVE-2016-2847
- EPSS 0.07%
- Veröffentlicht 27.04.2016 17:59:21
- Zuletzt bearbeitet 06.05.2026 22:30:45
fs/pipe.c in the Linux kernel before 4.5 does not limit the amount of unread data in pipes, which allows local users to cause a denial of service (memory consumption) by creating many pipes with non-default sizes.