Search Results (Refine Search)
- CPE Product Version: cpe:/o:google:android:6.0
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2015-1805 |
The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an "I/O vector array overrun." Published: August 08, 2015; 6:59:00 AM -0400 |
V3.x:(not available) V2.0: 7.2 HIGH |
CVE-2014-9322 |
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space. Published: December 17, 2014; 6:59:02 AM -0500 |
V3.1: 7.8 HIGH V2.0: 7.2 HIGH |