CVE-2019-5489
- EPSS 0.44%
- Veröffentlicht 07.01.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:45:02
The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allowing sniffing of secret information. (Fixing this af...
CVE-2019-3701
- EPSS 0.05%
- Veröffentlicht 03.01.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:21
An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dlc field. The privileged user "root" with CAP_NET_AD...
CVE-2018-20511
- EPSS 0.07%
- Veröffentlicht 27.12.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:38
An issue was discovered in the Linux kernel before 4.18.11. The ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain sensitive kernel address information by leveraging CAP_NET_ADMIN to read the ipddp_route dev and next f...
- EPSS 0.05%
- Veröffentlicht 18.12.2018 22:29:04
- Zuletzt bearbeitet 21.11.2024 03:53:31
A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container ...
CVE-2018-20169
- EPSS 0.12%
- Veröffentlicht 17.12.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:00
An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.
CVE-2018-19824
- EPSS 0.06%
- Veröffentlicht 03.12.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:37
In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malicious USB Sound device (with zero interfaces) that is mishandled in usb_audio_probe in sound/usb/card.c.
CVE-2018-16862
- EPSS 0.03%
- Veröffentlicht 26.11.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:28
A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removal). The new file created with the same inode may contain leftover pages from cleancache and the old file data ...
CVE-2018-9516
- EPSS 0.06%
- Veröffentlicht 06.11.2018 17:29:01
- Zuletzt bearbeitet 21.11.2024 04:15:37
In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for e...
CVE-2018-9363
- EPSS 0.05%
- Veröffentlicht 06.11.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:24
In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of bounds write with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kerne...
CVE-2018-9422
- EPSS 0.06%
- Veröffentlicht 06.11.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:26
In get_futex_key of futex.c, there is a use-after-free due to improper locking. This could lead to local escalation of privilege with no additional privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android...