VYPR

Kernel

by Linux

Source repositories

CVEs (18,613)

  • CVE-2014-1874Feb 28, 2014
    risk 0.00cvss epss 0.01

    The security_context_to_sid_core function in security/selinux/ss/services.c in the Linux kernel before 3.13.4 allows local users to cause a denial of service (system crash) by leveraging the CAP_MAC_ADMIN capability to set a zero-length security context.

  • CVE-2014-1690Feb 28, 2014
    risk 0.00cvss epss 0.04

    The help function in net/netfilter/nf_nat_irc.c in the Linux kernel before 3.12.8 allows remote attackers to obtain sensitive information from kernel memory by establishing an IRC DCC session in which incorrect packet data is transmitted during use of the NAT mangle feature.

  • CVE-2014-0069Feb 28, 2014
    risk 0.00cvss epss 0.00

    The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached write operations that copy fewer than the requested number of bytes, which allows local users to obtain sensitive information from kernel memory, cause a denial…

  • CVE-2013-4737Feb 15, 2014
    risk 0.00cvss epss 0.01

    The CONFIG_STRICT_MEMORY_RWX implementation for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly consider certain memory sections, which makes it easier for attackers to bypass intended…

  • CVE-2012-6638Feb 15, 2014
    risk 0.00cvss epss 0.03

    The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel before 3.2.24 allows remote attackers to cause a denial of service (kernel resource consumption) via a flood of SYN+FIN TCP packets, a different vulnerability than CVE-2012-2663.

  • CVE-2011-2909Feb 15, 2014
    risk 0.00cvss epss 0.00

    The do_devinfo_ioctl function in drivers/staging/comedi/comedi_fops.c in the Linux kernel before 3.1 allows local users to obtain sensitive information from kernel memory via a copy of a short string.

  • CVE-2014-0038Feb 6, 2014
    risk 0.00cvss epss 0.35

    The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privileges via a recvmmsg system call with a crafted timeout pointer parameter.

  • CVE-2014-1446Jan 18, 2014
    risk 0.00cvss epss 0.01

    The yam_ioctl function in drivers/net/hamradio/yam.c in the Linux kernel before 3.12.8 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability for an SIOCYAMGCFG ioctl…

  • CVE-2014-1445Jan 18, 2014
    risk 0.00cvss epss 0.00

    The wanxl_ioctl function in drivers/net/wan/wanxl.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via an ioctl call.

  • CVE-2014-1444Jan 18, 2014
    risk 0.00cvss epss 0.00

    The fst_get_iface function in drivers/net/wan/farsync.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability for an…

  • CVE-2014-1438Jan 18, 2014
    risk 0.00cvss epss 0.01

    The restore_fpu_checking function in arch/x86/include/asm/fpu-internal.h in the Linux kernel before 3.12.8 on the AMD K7 and K8 platforms does not clear pending exceptions before proceeding to an EMMS instruction, which allows local users to cause a denial of service (task kill)…

  • CVE-2013-7281Jan 8, 2014
    risk 0.00cvss epss 0.00

    The dgram_recvmsg function in net/ieee802154/dgram.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel stack memory via a…

  • CVE-2013-7271Jan 6, 2014
    risk 0.00cvss epss 0.00

    The x25_recvmsg function in net/x25/af_x25.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory via a (1) recvfrom,…

  • CVE-2013-7270Jan 6, 2014
    risk 0.00cvss epss 0.00

    The packet_recvmsg function in net/packet/af_packet.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory via a (1)…

  • CVE-2013-7269Jan 6, 2014
    risk 0.00cvss epss 0.00

    The nr_recvmsg function in net/netrom/af_netrom.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory via a (1)…

  • CVE-2013-7268Jan 6, 2014
    risk 0.00cvss epss 0.00

    The ipx_recvmsg function in net/ipx/af_ipx.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory via a (1) recvfrom,…

  • CVE-2013-7267Jan 6, 2014
    risk 0.00cvss epss 0.00

    The atalk_recvmsg function in net/appletalk/ddp.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory via a (1)…

  • CVE-2013-7266Jan 6, 2014
    risk 0.00cvss epss 0.00

    The mISDN_sock_recvmsg function in drivers/isdn/mISDN/socket.c in the Linux kernel before 3.12.4 does not ensure that a certain length value is consistent with the size of an associated data structure, which allows local users to obtain sensitive information from kernel memory…

  • CVE-2013-7265Jan 6, 2014
    risk 0.00cvss epss 0.00

    The pn_recvmsg function in net/phonet/datagram.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1)…

  • CVE-2013-7264Jan 6, 2014
    risk 0.00cvss epss 0.00

    The l2tp_ip_recvmsg function in net/l2tp/l2tp_ip.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1)…

Page 885 of 931