CVEs (14,504)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The oz_usb_handle_ep_data function in drivers/staging/ozwpan/ozusbsvc1.c in the OZWPAN driver in the Linux kernel through 4.0.5 allows remote attackers to cause a denial of service (divide-by-zero error and system crash)...Show more |
3Canonical LinuxOpensuse3Linux Kernel OpensuseUbuntu LinuxMay 6, 2026 Jun 7, 2015 N/A· v4 N/A· v3 9.0 HIGH· v2 drivers/staging/ozwpan/ozusbsvc1.c in the OZWPAN driver in the Linux kernel through 4.0.5 does not ensure that certain length values are sufficiently large, which allows remote attackers to cause a denial of service (sys...Show more |
Integer signedness error in the oz_hcd_get_desc_cnf function in drivers/staging/ozwpan/ozhcd.c in the OZWPAN driver in the Linux kernel through 4.0.5 allows remote attackers to cause a denial of service (system crash) or...Show more |
2Debian Linux2Debian Linux Linux KernelMay 6, 2026 May 27, 2015 N/A· v4 N/A· v3 6.2 MEDIUM· v2 Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and...Show more |
2Debian Linux2Debian Linux Linux KernelMay 6, 2026 May 27, 2015 N/A· v4 N/A· v3 4.9 MEDIUM· v2 A certain backport in the TCP Fast Open implementation for the Linux kernel before 3.18 does not properly maintain a count value, which allow local users to cause a denial of service (system crash) via the Fast Open feat...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 May 27, 2015 N/A· v4 N/A· v3 9.3 HIGH· v2 The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does not properly determine the memory locations used for encrypted data, which allows context-dependent attac...Show more |
5Debian FedoraprojectLinux+2 more6Debian Linux Enterprise MrgFedora+3 moreMay 6, 2026 May 27, 2015 N/A· v4 N/A· v3 3.3 LOW· v2 The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit settin...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 May 27, 2015 N/A· v4 N/A· v3 1.9 LOW· v2 arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protection mechanism via a cra...Show more |
2Fedoraproject Linux2Fedora Linux KernelMay 6, 2026 May 27, 2015 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Stack-based buffer overflow in the get_matching_model_microcode function in arch/x86/kernel/cpu/microcode/intel_early.c in the Linux kernel before 4.0 allows context-dependent attackers to gain privileges by constructing...Show more |
include/net/netfilter/nf_conntrack_extend.h in the netfilter subsystem in the Linux kernel before 3.14.5 uses an insufficiently large data type for certain extension data, which allows local users to cause a denial of se...Show more |
The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileg...Show more |
net/rds/sysctl.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other i...Show more |
3Debian LinuxSuse3Debian Linux Linux KernelSuse Linux Enterprise ServerMay 6, 2026 Apr 21, 2015 N/A· v4 N/A· v3 4.6 MEDIUM· v2 net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Apr 5, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 The IPv4 implementation in the Linux kernel before 3.18.8 does not properly consider the length of the Read-Copy Update (RCU) grace period for redirecting lookups in the absence of caching, which allows remote attackers...Show more |
The stack randomization feature in the Linux kernel before 3.19.1 on 64-bit platforms uses incorrect data types for the results of bitwise left-shift operations, which makes it easier for attackers to bypass the ASLR pro...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 Mar 16, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have u...Show more |
Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by chang...Show more |
The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replacement, which allows local users to cause a denial of service (transaction overrun and data corruption...Show more |
The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable.h in the Linux kernel before 3.13 on NUMA systems does not properly determine whether a Page Middle Directory (PMD) entry is a transparent h...Show more |
The filesystem implementation in the Linux kernel before 3.13 performs certain operations on lists of files with an inappropriate locking approach, which allows local users to cause a denial of service (soft lockup or sy...Show more |