CVE-2015-5697
- EPSS 0.06%
- Veröffentlicht 31.08.2015 10:59:14
- Zuletzt bearbeitet 06.05.2026 22:30:45
The get_bitmap_file function in drivers/md/md.c in the Linux kernel before 4.1.6 does not initialize a certain bitmap data structure, which allows local users to obtain sensitive information from kernel memory via a GET_BITMAP_FILE ioctl call.
CVE-2015-4700
- EPSS 0.08%
- Veröffentlicht 31.08.2015 10:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The bpf_int_jit_compile function in arch/x86/net/bpf_jit_comp.c in the Linux kernel before 4.0.6 allows local users to cause a denial of service (system crash) by creating a packet filter and then loading crafted BPF instructions that trigger late co...
CVE-2015-3212
- EPSS 0.08%
- Veröffentlicht 31.08.2015 10:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in net/sctp/socket.c in the Linux kernel before 4.1.2 allows local users to cause a denial of service (list corruption and panic) via a rapid series of system calls related to sockets, as demonstrated by setsockopt calls.
CVE-2015-1805
- EPSS 14.78%
- Veröffentlicht 08.08.2015 10:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a den...
CVE-2015-3636
- EPSS 3.04%
- Veröffentlicht 06.08.2015 01:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data structure during an unhash operation, which allows local users to gain privileges or cause a denial of service (use-after-free and sy...
CVE-2015-4167
- EPSS 0.05%
- Veröffentlicht 05.08.2015 18:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.19.1 does not validate certain length values, which allows local users to cause a denial of service (incorrect data representation or integer overflow, and OOPS) via a crafted...
CVE-2015-3339
- EPSS 0.03%
- Veröffentlicht 27.05.2015 10:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but t...
CVE-2015-3331
- EPSS 4.11%
- Veröffentlicht 27.05.2015 10:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does not properly determine the memory locations used for encrypted data, which allows context-dependent attackers to cause a denial of serv...
CVE-2015-2830
- EPSS 0.04%
- Veröffentlicht 27.05.2015 10:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protection mechanism via a crafted application that uses the...
CVE-2015-2922
- EPSS 1.72%
- Veröffentlicht 27.05.2015 10:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value ...