Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown

CVE-2020-25656

Disclosure Date: December 02, 2020 (last updated February 22, 2025)
A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is to data confidentiality.
Attacker Value
Unknown

CVE-2020-25704

Disclosure Date: December 02, 2020 (last updated February 22, 2025)
A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER. A local user could use this flaw to starve the resources causing denial of service.
Attacker Value
Unknown

CVE-2020-25643

Disclosure Date: October 06, 2020 (last updated February 22, 2025)
A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Attacker Value
Unknown

CVE-2020-0427

Disclosure Date: September 17, 2020 (last updated February 22, 2025)
In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-140550171
Attacker Value
Unknown

CVE-2020-14314

Disclosure Date: September 15, 2020 (last updated February 22, 2025)
A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a directory with broken indexing. This flaw allows a local user to crash the system if the directory exists. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2020-24394

Disclosure Date: August 19, 2020 (last updated February 22, 2025)
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current umask is not considered.
Attacker Value
Unknown

CVE-2018-18585

Disclosure Date: October 23, 2018 (last updated November 27, 2024)
chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).
Attacker Value
Unknown

CVE-2018-18584

Disclosure Date: October 23, 2018 (last updated November 27, 2024)
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
Attacker Value
Unknown

CVE-2018-16737

Disclosure Date: October 10, 2018 (last updated November 08, 2023)
tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation.
Attacker Value
Unknown

CVE-2018-16738

Disclosure Date: October 10, 2018 (last updated November 08, 2023)
tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed in 1.1.