CVE-2016-4470
- EPSS 0.06%
- Veröffentlicht 27.06.2016 10:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a craft...
CVE-2016-4440
- EPSS 0.05%
- Veröffentlicht 27.06.2016 10:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
arch/x86/kvm/vmx.c in the Linux kernel through 4.6.3 mishandles the APICv on/off state, which allows guest OS users to obtain direct APIC MSR access on the host OS, and consequently cause a denial of service (host OS crash) or possibly execute arbitr...
CVE-2016-3713
- EPSS 0.06%
- Veröffentlicht 27.06.2016 10:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Linux kernel before 4.6.1 supports MSR 0x2f8, which allows guest OS users to read or write to the kvm_arch_vcpu data structure, and consequently obtain sensitive information or cause a denial ...
CVE-2016-1583
- EPSS 0.44%
- Veröffentlicht 27.06.2016 10:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames...
CVE-2016-0758
- EPSS 0.15%
- Veröffentlicht 27.06.2016 10:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.
CVE-2014-9903
- EPSS 0.05%
- Veröffentlicht 27.06.2016 10:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The sched_read_attr function in kernel/sched/core.c in the Linux kernel 3.14-rc before 3.14-rc4 uses an incorrect size, which allows local users to obtain sensitive information from kernel stack memory via a crafted sched_getattr system call.
CVE-2016-4951
- EPSS 0.11%
- Veröffentlicht 23.05.2016 10:59:15
- Zuletzt bearbeitet 06.05.2026 22:30:45
The tipc_nl_publ_dump function in net/tipc/socket.c in the Linux kernel through 4.6 does not verify socket existence, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other...
CVE-2016-4913
- EPSS 0.08%
- Veröffentlicht 23.05.2016 10:59:14
- Zuletzt bearbeitet 06.05.2026 22:30:45
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have...
CVE-2016-4805
- EPSS 0.13%
- Veröffentlicht 23.05.2016 10:59:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a n...
CVE-2016-4794
- EPSS 0.09%
- Veröffentlicht 23.05.2016 10:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in mm/percpu.c in the Linux kernel through 4.6 allows local users to cause a denial of service (BUG) or possibly have unspecified other impact via crafted use of the mmap and bpf system calls.