Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 28

Количество 28

fstec логотип

BDU:2014-00053

больше 12 лет назад

Уязвимость операционной системы Linux, позволяющая злоумышленнику получить доступ к защищаемой информации

CVSS2: 7.2
EPSS: Низкий
altlinux логотип

ALT-PU-2014-3217

больше 12 лет назад

ALT-PU-2014-3217: package `kernel-image-std-def` update to version 3.12.20-alt1

CVSS2: 7.2
EPSS: Низкий
altlinux логотип

ALT-PU-2014-1605

больше 12 лет назад

ALT-PU-2014-1605: package `kernel-image-led-vs` update to version 3.13.11-alt12

CVSS2: 10
EPSS: Низкий
altlinux логотип

ALT-PU-2014-1604

больше 12 лет назад

ALT-PU-2014-1604: package `kernel-image-led-ws` update to version 3.13.11-alt12

CVSS2: 10
EPSS: Низкий
altlinux логотип

ALT-PU-2014-1634

больше 12 лет назад

ALT-PU-2014-1634: package `kernel-image-un-def` update to version 3.14.4-alt1

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2014-1737

больше 12 лет назад

The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device. First, raw_cmd_ioctl calls raw_cmd_copyin. This function kmallocs space for a floppy_raw_cmd structure and stores the resulting allocation in the "rcmd" pointer argument. It then attempts to copy_from_user the structure from userspace. If this fails, an early EFAULT return is taken. The problem is that even if the early return is taken, the pointer to the non-/partially-initialized floppy_raw_cmd structure has already been returned via the "rcmd" pointer. Back out in raw_cmd_ioctl, it attempts to raw_cmd_free this pointer. raw_cmd_free attempts to free any DMA pages allocated for the raw command, kfrees the raw command structure itself, and follows the linked list, if any, of further raw com...

CVSS2: 7.2
EPSS: Низкий
redhat логотип

CVE-2014-1737

больше 12 лет назад

The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device.

CVSS2: 6.6
EPSS: Низкий
nvd логотип

CVE-2014-1737

больше 12 лет назад

The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device.

CVSS2: 7.2
EPSS: Низкий
debian логотип

CVE-2014-1737

больше 12 лет назад

The raw_cmd_copyin function in drivers/block/floppy.c in the Linux ker ...

CVSS2: 7.2
EPSS: Низкий
github логотип

GHSA-vmrj-8qgc-5x6c

больше 4 лет назад

The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device.

EPSS: Низкий
fstec логотип

BDU:2014-00334

больше 12 лет назад

Уязвимость операционной системы Linux, позволяющая злоумышленнику вызвать отказ в обслуживании или повысить свои привилегии

CVSS2: 7.2
EPSS: Низкий
fstec логотип

BDU:2014-00110

больше 12 лет назад

Уязвимость операционной системы Linux, позволяющая злоумышленнику повысить свои привилегии

CVSS2: 7.2
EPSS: Низкий
altlinux логотип

ALT-PU-2014-1802

больше 12 лет назад

ALT-PU-2014-1802: package `kernel-image-el-def` update to version 2.6.32-alt25

CVSS3: 7.8
EPSS: Низкий
altlinux логотип

ALT-PU-2014-1820

около 12 лет назад

ALT-PU-2014-1820: package `kernel-image-el7-def` update to version 3.10.0-alt9

CVSS3: 7.8
EPSS: Низкий
oracle-oval логотип

ELSA-2014-3041

больше 12 лет назад

ELSA-2014-3041: unbreakable enterprise kernel security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2014-0740

больше 12 лет назад

ELSA-2014-0740: kernel security and bug fix update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2014-0740-1

больше 12 лет назад

ELSA-2014-0740-1: kernel security and bug fix update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2014-3043

больше 12 лет назад

ELSA-2014-3043: unbreakable enterprise kernel security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2014-3042

больше 12 лет назад

ELSA-2014-3042: unbreakable enterprise kernel security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2014-0771

больше 12 лет назад

ELSA-2014-0771: kernel security and bug fix update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2014-00053

Уязвимость операционной системы Linux, позволяющая злоумышленнику получить доступ к защищаемой информации

CVSS2: 7.2
0%
Низкий
больше 12 лет назад
altlinux логотип
ALT-PU-2014-3217

ALT-PU-2014-3217: package `kernel-image-std-def` update to version 3.12.20-alt1

CVSS2: 7.2
0%
Низкий
больше 12 лет назад
altlinux логотип
ALT-PU-2014-1605

ALT-PU-2014-1605: package `kernel-image-led-vs` update to version 3.13.11-alt12

CVSS2: 10
больше 12 лет назад
altlinux логотип
ALT-PU-2014-1604

ALT-PU-2014-1604: package `kernel-image-led-ws` update to version 3.13.11-alt12

CVSS2: 10
больше 12 лет назад
altlinux логотип
ALT-PU-2014-1634

ALT-PU-2014-1634: package `kernel-image-un-def` update to version 3.14.4-alt1

CVSS3: 5.5
больше 12 лет назад
ubuntu логотип
CVE-2014-1737

The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device. First, raw_cmd_ioctl calls raw_cmd_copyin. This function kmallocs space for a floppy_raw_cmd structure and stores the resulting allocation in the "rcmd" pointer argument. It then attempts to copy_from_user the structure from userspace. If this fails, an early EFAULT return is taken. The problem is that even if the early return is taken, the pointer to the non-/partially-initialized floppy_raw_cmd structure has already been returned via the "rcmd" pointer. Back out in raw_cmd_ioctl, it attempts to raw_cmd_free this pointer. raw_cmd_free attempts to free any DMA pages allocated for the raw command, kfrees the raw command structure itself, and follows the linked list, if any, of further raw com...

CVSS2: 7.2
0%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-1737

The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device.

CVSS2: 6.6
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1737

The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device.

CVSS2: 7.2
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1737

The raw_cmd_copyin function in drivers/block/floppy.c in the Linux ker ...

CVSS2: 7.2
0%
Низкий
больше 12 лет назад
github логотип
GHSA-vmrj-8qgc-5x6c

The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device.

0%
Низкий
больше 4 лет назад
fstec логотип
BDU:2014-00334

Уязвимость операционной системы Linux, позволяющая злоумышленнику вызвать отказ в обслуживании или повысить свои привилегии

CVSS2: 7.2
0%
Низкий
больше 12 лет назад
fstec логотип
BDU:2014-00110

Уязвимость операционной системы Linux, позволяющая злоумышленнику повысить свои привилегии

CVSS2: 7.2
0%
Низкий
больше 12 лет назад
altlinux логотип
ALT-PU-2014-1802

ALT-PU-2014-1802: package `kernel-image-el-def` update to version 2.6.32-alt25

CVSS3: 7.8
больше 12 лет назад
altlinux логотип
ALT-PU-2014-1820

ALT-PU-2014-1820: package `kernel-image-el7-def` update to version 3.10.0-alt9

CVSS3: 7.8
около 12 лет назад
oracle-oval логотип
ELSA-2014-3041

ELSA-2014-3041: unbreakable enterprise kernel security update (IMPORTANT)

больше 12 лет назад
oracle-oval логотип
ELSA-2014-0740

ELSA-2014-0740: kernel security and bug fix update (IMPORTANT)

больше 12 лет назад
oracle-oval логотип
ELSA-2014-0740-1

ELSA-2014-0740-1: kernel security and bug fix update (IMPORTANT)

больше 12 лет назад
oracle-oval логотип
ELSA-2014-3043

ELSA-2014-3043: unbreakable enterprise kernel security update (IMPORTANT)

больше 12 лет назад
oracle-oval логотип
ELSA-2014-3042

ELSA-2014-3042: unbreakable enterprise kernel security update (IMPORTANT)

больше 12 лет назад
oracle-oval логотип
ELSA-2014-0771

ELSA-2014-0771: kernel security and bug fix update (IMPORTANT)

больше 12 лет назад

Уязвимостей на страницу