CVE-2016-3135
- EPSS 1%
- Veröffentlicht 27.04.2016 17:59:23
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLA...
CVE-2016-3134
- EPSS 1.23%
- Veröffentlicht 27.04.2016 17:59:22
- Zuletzt bearbeitet 06.05.2026 22:30:45
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
CVE-2016-2184
- EPSS 1.95%
- Veröffentlicht 27.04.2016 17:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference or double free, and system crash) v...
CVE-2016-2143
- EPSS 0.56%
- Veröffentlicht 27.04.2016 17:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted appli...
CVE-2016-3961
- EPSS 0.51%
- Veröffentlicht 15.04.2016 14:59:14
- Zuletzt bearbeitet 06.05.2026 22:30:45
Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to access a hugetlbfs mapped area.
CVE-2015-8553
- EPSS 0.38%
- Veröffentlicht 13.04.2016 15:59:07
- Zuletzt bearbeitet 26.05.2026 18:16:35
Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0777.
CVE-2016-3157
- EPSS 0.51%
- Veröffentlicht 12.04.2016 16:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel does not properly context-switch IOPL on 64-bit PV Xen guests, which allows local guest OS users to gain privileges, cause a denial of service (guest OS crash), or obtain se...
- EPSS 0.4%
- Veröffentlicht 08.02.2016 03:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain privileges by establishing a user namespace, waiting for a root process to enter that namespace with an unsafe uid or gid, and then us...
CVE-2015-7509
- EPSS 0.41%
- Veröffentlicht 28.12.2015 11:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015.
CVE-2015-7833
- EPSS 0.68%
- Veröffentlicht 19.10.2015 10:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.10.0-229.14.1.el7 in Red Hat Enterprise Linux (RHEL) 7.1 allows physically proximate attackers to cause a denial of service (panic) via a nonzero bInterfaceNumber value in...