CVE-2014-7975
|
The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call.
Published:
October 13, 2014; 06:55:09 AM -04:00
|
V2: 4.9 MEDIUM
|
CVE-2014-7970
|
The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both arguments to the pivot_root system call.
Published:
October 13, 2014; 06:55:08 AM -04:00
|
V2: 4.9 MEDIUM
|
CVE-2014-7283
|
The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementation in the Linux kernel before 3.14.2 does not properly compare btree hash values, which allows local users to cause a denial of service (filesystem corruption, and OOPS or panic) via operations on directories that have hash collisions, as demonstrated by rmdir operations.
Published:
October 13, 2014; 06:55:08 AM -04:00
|
V2: 4.9 MEDIUM
|
CVE-2014-3535
|
include/linux/netdevice.h in the Linux kernel before 2.6.36 incorrectly uses macros for netdev_printk and its related logging implementation, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) by sending invalid packets to a VxLAN interface.
Published:
September 28, 2014; 03:55:05 PM -04:00
|
V2: 7.8 HIGH
|
CVE-2014-0205
|
The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does not properly maintain a certain reference count during requeue operations, which allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that triggers a zero count.
Published:
September 28, 2014; 03:55:05 PM -04:00
|
V2: 6.9 MEDIUM
|
CVE-2014-7145
|
The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer dereference and client system crash) or possibly have unspecified other impact by deleting the IPC$ share during resolution of DFS referrals.
Published:
September 28, 2014; 06:55:10 AM -04:00
|
V2: 7.8 HIGH
|
CVE-2014-6418
|
net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from the IP address of a Ceph Monitor.
Published:
September 28, 2014; 06:55:10 AM -04:00
|
V2: 7.1 HIGH
|
CVE-2014-6417
|
net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly consider the possibility of kmalloc failure, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via a long unencrypted auth ticket.
Published:
September 28, 2014; 06:55:10 AM -04:00
|
V2: 7.8 HIGH
|
CVE-2014-6416
|
Buffer overflow in net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, allows remote attackers to cause a denial of service (memory corruption and panic) or possibly have unspecified other impact via a long unencrypted auth ticket.
Published:
September 28, 2014; 06:55:10 AM -04:00
|
V2: 7.8 HIGH
|
CVE-2014-6410
|
The __udf_read_inode function in fs/udf/inode.c in the Linux kernel through 3.16.3 does not restrict the amount of ICB indirection, which allows physically proximate attackers to cause a denial of service (infinite loop or stack consumption) via a UDF filesystem with a crafted inode.
Published:
September 28, 2014; 06:55:10 AM -04:00
|
V2: 4.7 MEDIUM
|
CVE-2014-3631
|
The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16.3 does not properly implement garbage collection, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via multiple "keyctl newring" operations followed by a "keyctl timeout" operation.
Published:
September 28, 2014; 06:55:10 AM -04:00
|
V2: 7.2 HIGH
|
CVE-2014-3186
|
Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as used in Android on Nexus 7 devices, allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that sends a large report.
Published:
September 28, 2014; 06:55:10 AM -04:00
|
V2: 6.9 MEDIUM
|
CVE-2014-3185
|
Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat.c in the Whiteheat USB Serial Driver in the Linux kernel before 3.16.2 allow physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with a bulk response.
Published:
September 28, 2014; 06:55:10 AM -04:00
|
V2: 6.9 MEDIUM
|
CVE-2014-3184
|
The report_fixup functions in the HID subsystem in the Linux kernel before 3.16.2 might allow physically proximate attackers to cause a denial of service (out-of-bounds write) via a crafted device that provides a small report descriptor, related to (1) drivers/hid/hid-cherry.c, (2) drivers/hid/hid-kye.c, (3) drivers/hid/hid-lg.c, (4) drivers/hid/hid-monterey.c, (5) drivers/hid/hid-petalynx.c, and (6) drivers/hid/hid-sunplus.c.
Published:
September 28, 2014; 06:55:10 AM -04:00
|
V2: 4.7 MEDIUM
|
CVE-2014-3183
|
Heap-based buffer overflow in the logi_dj_ll_raw_request function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that specifies a large report size for an LED report.
Published:
September 28, 2014; 06:55:10 AM -04:00
|
V2: 6.9 MEDIUM
|
CVE-2014-3182
|
Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provides a malformed REPORT_TYPE_NOTIF_DEVICE_UNPAIRED value.
Published:
September 28, 2014; 06:55:10 AM -04:00
|
V2: 6.9 MEDIUM
|
CVE-2014-3181
|
Multiple stack-based buffer overflows in the magicmouse_raw_event function in drivers/hid/hid-magicmouse.c in the Magic Mouse HID driver in the Linux kernel through 3.16.3 allow physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with an event.
Published:
September 28, 2014; 06:55:10 AM -04:00
|
V2: 6.9 MEDIUM
|
CVE-2012-6657
|
The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.
Published:
September 28, 2014; 06:55:10 AM -04:00
|
V2: 4.9 MEDIUM
|
CVE-2014-3985
|
The getHTTPResponse function in miniwget.c in MiniUPnP 1.9 allows remote attackers to cause a denial of service (crash) via crafted headers that trigger an out-of-bounds read.
Published:
September 11, 2014; 02:55:06 PM -04:00
|
V2: 5.0 MEDIUM
|
CVE-2014-0554
|
Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to bypass intended access restrictions via unspecified vectors.
Published:
September 10, 2014; 06:55:06 AM -04:00
|
V2: 10.0 HIGH
|