CVE-2017-16939
- EPSS 10.16%
- Veröffentlicht 24.11.2017 10:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted SO_RCVBUF setsockopt system call in conjunction with XFRM...
CVE-2017-12190
- EPSS 0.08%
- Veröffentlicht 22.11.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The bio_map_user_iov and bio_unmap_user functions in block/bio.c in the Linux kernel before 4.13.8 do unbalanced refcounting when a SCSI I/O vector has small consecutive buffers belonging to the same page. The bio_add_pc_page function merges them int...
CVE-2017-0861
- EPSS 0.09%
- Veröffentlicht 16.11.2017 23:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
Use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem in the Linux kernel allows attackers to gain privileges via unspecified vectors.
CVE-2017-15115
- EPSS 0.05%
- Veröffentlicht 15.11.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possi...
CVE-2017-16643
- EPSS 0.03%
- Veröffentlicht 07.11.2017 23:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The parse_hid_report_descriptor function in drivers/input/tablet/gtco.c in the Linux kernel before 4.13.11 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted U...
CVE-2017-16649
- EPSS 0.08%
- Veröffentlicht 07.11.2017 23:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The usbnet_generic_cdc_bind function in drivers/net/usb/cdc_ether.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (divide-by-zero error and system crash) or possibly have unspecified other impact via a crafted US...
CVE-2017-16532
- EPSS 0.09%
- Veröffentlicht 04.11.2017 01:29:37
- Zuletzt bearbeitet 13.05.2026 00:24:29
The get_endpoints function in drivers/usb/misc/usbtest.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB devic...
CVE-2017-16533
- EPSS 0.11%
- Veröffentlicht 04.11.2017 01:29:37
- Zuletzt bearbeitet 13.05.2026 00:24:29
The usbhid_parse function in drivers/hid/usbhid/hid-core.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.
CVE-2017-16535
- EPSS 0.11%
- Veröffentlicht 04.11.2017 01:29:37
- Zuletzt bearbeitet 13.05.2026 00:24:29
The usb_get_bos_descriptor function in drivers/usb/core/config.c in the Linux kernel before 4.13.10 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB devi...
CVE-2017-16536
- EPSS 0.09%
- Veröffentlicht 04.11.2017 01:29:37
- Zuletzt bearbeitet 13.05.2026 00:24:29
The cx231xx_usb_probe function in drivers/media/usb/cx231xx/cx231xx-cards.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via ...