Vulnerabilities > Linux > Linux Kernel > 4.15.9

DATE CVE VULNERABILITY TITLE RISK
2019-05-28 CVE-2019-12382 NULL Pointer Dereference vulnerability in Linux Kernel
An issue was discovered in drm_load_edid_firmware in drivers/gpu/drm/drm_edid_load.c in the Linux kernel through 5.1.5.
local
low complexity
linux CWE-476
5.5
2019-05-28 CVE-2019-12381 NULL Pointer Dereference vulnerability in Linux Kernel
An issue was discovered in ip_ra_control in net/ipv4/ip_sockglue.c in the Linux kernel through 5.1.5.
local
low complexity
linux CWE-476
5.5
2019-05-28 CVE-2019-12380 7PK - Errors vulnerability in Linux Kernel
**DISPUTED** An issue was discovered in the efi subsystem in the Linux kernel through 5.1.5.
local
low complexity
linux CWE-388
5.5
2019-05-28 CVE-2019-12379 Memory Leak vulnerability in Linux Kernel
An issue was discovered in con_insert_unipair in drivers/tty/vt/consolemap.c in the Linux kernel through 5.1.5.
local
low complexity
linux CWE-401
5.5
2019-05-28 CVE-2019-12378 NULL Pointer Dereference vulnerability in Linux Kernel
An issue was discovered in ip6_ra_control in net/ipv6/ipv6_sockglue.c in the Linux kernel through 5.1.5.
local
low complexity
linux CWE-476
5.5
2019-05-15 CVE-2019-11833 Use of Uninitialized Resource vulnerability in multiple products
fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.
5.5
2019-05-10 CVE-2019-11884 The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character. 3.3
2019-05-07 CVE-2019-11810 Use After Free vulnerability in multiple products
An issue was discovered in the Linux kernel before 5.0.7.
network
low complexity
linux canonical debian CWE-416
7.5
2019-05-07 CVE-2018-20836 Use After Free vulnerability in multiple products
An issue was discovered in the Linux kernel before 4.20.
network
high complexity
linux canonical debian f5 netapp opensuse CWE-416
8.1
2019-04-29 CVE-2019-11599 Improper Locking vulnerability in Linux Kernel
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags changes while it runs, which allows local users to obtain sensitive information, cause a denial of service, or possibly have unspecified other impact by triggering a race condition with mmget_not_zero or get_task_mm calls.
local
high complexity
linux CWE-667
7.0