CVE-2016-7425
- EPSS 0.43%
- Veröffentlicht 16.10.2016 21:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
The arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel through 4.8.2 does not restrict a certain length field, which allows local users to gain privileges or cause a denial of service (heap-based buffer overflow)...
CVE-2016-7097
- EPSS 0.38%
- Veröffentlicht 16.10.2016 21:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
The filesystem implementation in the Linux kernel through 4.8.2 preserves the setgid bit during a setxattr call, which allows local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permission...
CVE-2016-7042
- EPSS 0.4%
- Veröffentlicht 16.10.2016 21:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The proc_keys_show function in security/keys/proc.c in the Linux kernel through 4.8.2, when the GNU Compiler Collection (gcc) stack protector is enabled, uses an incorrect buffer size for certain timeout data, which allows local users to cause a deni...
CVE-2016-7039
- EPSS 7.61%
- Veröffentlicht 16.10.2016 21:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
The IP stack in the Linux kernel through 4.8.2 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GRO path for large crafted packets, as demonstrated b...
CVE-2016-6828
- EPSS 1.18%
- Veröffentlicht 16.10.2016 21:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The tcp_check_send_head function in include/net/tcp.h in the Linux kernel before 4.7.5 does not properly maintain certain SACK state after a failed data copy, which allows local users to cause a denial of service (tcp_xmit_retransmit_queue use-after-...
CVE-2016-6327
- EPSS 0.39%
- Veröffentlicht 16.10.2016 21:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
drivers/infiniband/ulp/srpt/ib_srpt.c in the Linux kernel before 4.5.1 allows local users to cause a denial of service (NULL pointer dereference and system crash) by using an ABORT_TASK command to abort a device write operation.
CVE-2015-8952
- EPSS 0.45%
- Veröffentlicht 16.10.2016 21:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4.6 mishandles xattr block caching, which allows local users to cause a denial of service (soft lockup) via filesystem operations in environments that use ...
- EPSS 24.3%
- Veröffentlicht 10.10.2016 11:00:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.
CVE-2015-8956
- EPSS 0.22%
- Veröffentlicht 10.10.2016 10:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in the Linux kernel before 4.2 allows local users to obtain sensitive information or cause a denial of service (NULL pointer dereference) via vectors involving a bind system call on a Bluet...
CVE-2016-0617
- EPSS 0.34%
- Veröffentlicht 30.09.2016 14:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Unspecified vulnerability in the kernel-uek component in Oracle Linux 6 allows local users to affect availability via unknown vectors.