CVE-2014-9904
- EPSS 0.04%
- Veröffentlicht 27.06.2016 10:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.17 does not properly check for an integer overflow, which allows local users to cause a denial of service (insufficient memory a...
CVE-2016-4913
- EPSS 0.08%
- Veröffentlicht 23.05.2016 10:59:14
- Zuletzt bearbeitet 06.05.2026 22:30:45
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have...
CVE-2016-4805
- EPSS 0.13%
- Veröffentlicht 23.05.2016 10:59:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a n...
CVE-2016-4581
- EPSS 0.05%
- Veröffentlicht 23.05.2016 10:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
fs/pnode.c in the Linux kernel before 4.5.4 does not properly traverse a mount propagation tree in a certain case involving a slave mount, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted series ...
CVE-2016-4580
- EPSS 1.31%
- Veröffentlicht 23.05.2016 10:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The x25_negotiate_facilities function in net/x25/x25_facilities.c in the Linux kernel before 4.5.5 does not properly initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory via an X.25 Call...
CVE-2016-4578
- EPSS 0.17%
- Veröffentlicht 23.05.2016 10:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_t...
CVE-2016-4569
- EPSS 0.37%
- Veröffentlicht 23.05.2016 10:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer...
CVE-2016-4565
- EPSS 0.25%
- Veröffentlicht 23.05.2016 10:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI int...
CVE-2016-4486
- EPSS 0.52%
- Veröffentlicht 23.05.2016 10:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.
CVE-2016-4485
- EPSS 0.46%
- Veröffentlicht 23.05.2016 10:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.