CVE-2016-5696
- EPSS 51.99%
- Veröffentlicht 06.08.2016 20:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.
CVE-2016-5412
- EPSS 0.05%
- Veröffentlicht 06.08.2016 20:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
arch/powerpc/kvm/book3s_hv_rmhandlers.S in the Linux kernel through 4.7 on PowerPC platforms, when CONFIG_KVM_BOOK3S_64_HV is enabled, allows guest OS users to cause a denial of service (host OS infinite loop) by making a H_CEDE hypercall during the ...
CVE-2016-5400
- EPSS 0.08%
- Veröffentlicht 06.08.2016 20:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy.c in the airspy USB driver in the Linux kernel before 4.7 allows local users to cause a denial of service (memory consumption) via a crafted USB device that emulates many VFL...
CVE-2015-8944
- EPSS 0.06%
- Veröffentlicht 06.08.2016 10:59:54
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ioresources_init function in kernel/resource.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 6 and 7 (2013) devices, uses weak permissions for /proc/iomem, which allows local users to obtain sensitive information ...
CVE-2014-9900
- EPSS 0.08%
- Veröffentlicht 06.08.2016 10:59:44
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ethtool_get_wol function in net/core/ethtool.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not initialize a certain data structure, which allows local users to obtain sensitive infor...
CVE-2014-9895
- EPSS 0.09%
- Veröffentlicht 06.08.2016 10:59:39
- Zuletzt bearbeitet 06.05.2026 22:30:45
drivers/media/media-device.c in the Linux kernel before 3.11, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly initialize certain data structures, which allows local users to obtain sensitive information via a c...
CVE-2014-9892
- EPSS 0.1%
- Veröffentlicht 06.08.2016 10:59:35
- Zuletzt bearbeitet 06.05.2026 22:30:45
The snd_compr_tstamp function in sound/core/compress_offload.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly initialize a timestamp data structure, which allows attackers to o...
CVE-2014-9888
- EPSS 0.11%
- Veröffentlicht 06.08.2016 10:59:31
- Zuletzt bearbeitet 06.05.2026 22:30:45
arch/arm/mm/dma-mapping.c in the Linux kernel before 3.13 on ARM platforms, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not prevent executable DMA mappings, which might allow local users to gain privileges via a crafted...
CVE-2014-9870
- EPSS 0.08%
- Veröffentlicht 06.08.2016 10:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Linux kernel before 3.11 on ARM platforms, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly consider user-space access to the TPIDRURW register, which allows local users to gain privileges via a crafted appl...
CVE-2016-6130
- EPSS 0.06%
- Veröffentlicht 03.07.2016 21:59:18
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in the sclp_ctl_ioctl_sccb function in drivers/s390/char/sclp_ctl.c in the Linux kernel before 4.6 allows local users to obtain sensitive information from kernel memory by changing a certain length value, aka a "double fetch" vulnerabi...