CVE-2017-9242
- EPSS 0.05%
- Veröffentlicht 27.05.2017 01:29:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel through 4.11.3 is too late in checking whether an overwrite of an skb data structure may occur, which allows local users to cause a denial of service (system crash) via craft...
CVE-2017-9077
- EPSS 0.96%
- Veröffentlicht 19.05.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related is...
CVE-2017-9074
- EPSS 0.07%
- Veröffentlicht 19.05.2017 07:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid option, which allows local users to cause a denial of service (out-of-bounds read and BUG) or possibly...
CVE-2017-9075
- EPSS 0.07%
- Veröffentlicht 19.05.2017 07:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related is...
CVE-2017-9076
- EPSS 0.07%
- Veröffentlicht 19.05.2017 07:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related i...
CVE-2017-7495
- EPSS 0.05%
- Veröffentlicht 15.05.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-before-commit list, which allows local users to obtain sensitive information from other users' files in opportunistic circumstances by ...
CVE-2017-7487
- EPSS 0.08%
- Veröffentlicht 14.05.2017 22:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel through 4.11.1 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a failed SIOCGIFADDR io...
CVE-2017-8924
- EPSS 0.11%
- Veröffentlicht 12.05.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel before 4.10.4 allows local users to obtain sensitive information (in the dmesg ringbuffer and syslog) from uninitialized kernel memory by using a crafted USB device ...
CVE-2017-8925
- EPSS 0.11%
- Veröffentlicht 12.05.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows local users to cause a denial of service (tty exhaustion) by leveraging reference count mishandling.
CVE-2017-0627
- EPSS 0.34%
- Veröffentlicht 12.05.2017 15:29:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
An information disclosure vulnerability in the kernel UVC driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. ...