Skip to main content

Vendor archive

linux CVEs

Beta · best-effort

18,718 CVEs tagged to vendor linux1,022 Critical, 6,153 High, 10,969 Medium, 574 Low, 0 Unrated.

CVE-2013-2634

Published Mar 22, 2013

net/dcb/dcbnl.c in the Linux kernel before 3.8.4 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a cr…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-1860

Published Mar 22, 2013

Heap-based buffer overflow in the wdm_in_callback function in drivers/usb/class/cdc-wdm.c in the Linux kernel before 3.8.4 allows physically proximate attackers to cause a denial…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1848

Published Mar 22, 2013

fs/ext3/super.c in the Linux kernel before 3.8.4 uses incorrect arguments to functions in certain circumstances related to printk input, which allows local users to conduct format…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1828

Published Mar 22, 2013

The sctp_getsockopt_assoc_stats function in net/sctp/socket.c in the Linux kernel before 3.8.4 does not validate a size value before proceeding to a copy_from_user operation, whic…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1827

Published Mar 22, 2013

net/dccp/ccid.h in the Linux kernel before 3.5.4 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the C…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1826

Published Mar 22, 2013

The xfrm_state_netlink function in net/xfrm/xfrm_user.c in the Linux kernel before 3.5.7 does not properly handle error conditions in dump_one_state function calls, which allows l…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1798

Published Mar 22, 2013

The ioapic_read_indirect function in virt/kvm/ioapic.c in the Linux kernel through 3.8.4 does not properly handle a certain combination of invalid IOAPIC_REG_SELECT and IOAPIC_REG…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1797

Published Mar 22, 2013

Use-after-free vulnerability in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 allows guest OS users to cause a denial of service (host OS memory corruption) or possibly hav…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1796

Published Mar 22, 2013

The kvm_set_msr_common function in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 does not ensure a required time_page alignment during an MSR_KVM_SYSTEM_TIME operation, whi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1792

Published Mar 22, 2013

Race condition in the install_user_keyrings function in security/keys/process_keys.c in the Linux kernel before 3.8.3 allows local users to cause a denial of service (NULL pointer…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0914

Published Mar 22, 2013

The flush_signal_handlers function in kernel/signal.c in the Linux kernel before 3.8.4 preserves the value of the sa_restorer field across an exec operation, which makes it easier…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-0913

Published Mar 18, 2013

Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through 3.8.3, as used in Goo…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2548

Published Mar 15, 2013

The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect length value duri…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-2547

Published Mar 15, 2013

The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 does not initialize certain structu…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-2546

Published Mar 15, 2013

The report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect C library function for copying strings, which allows local users to obtain…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-6549

Published Mar 15, 2013

The isofs_export_encode_fh function in fs/isofs/export.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitiv…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-6547

Published Mar 15, 2013

The __tun_chr_ioctl function in drivers/net/tun.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-6543

Published Mar 15, 2013

The l2tp_ip6_getname function in net/l2tp/l2tp_ip6.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive in…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-6541

Published Mar 15, 2013

The ccid3_hc_tx_getsockopt function in net/dccp/ccids/ccid3.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-6540

Published Mar 15, 2013

The do_ip_vs_get_ctl function in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 3.6 does not initialize a certain structure for IP_VS_SO_GET_TIMEOUT commands, which all…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort
Showing 17,326-17,350 of 18,718 CVEsPage 694 of 749