Vulnerabilities > Linux

DATE CVE VULNERABILITY TITLE RISK
2020-02-06 CVE-2020-8647 Use After Free vulnerability in multiple products
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.
local
low complexity
linux debian opensuse CWE-416
6.1
2020-01-31 CVE-2019-3016 Race Condition vulnerability in Linux Kernel
In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest.
local
high complexity
linux CWE-362
4.7
2020-01-29 CVE-2020-8428 Use After Free vulnerability in Linux Kernel
fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a denial of service (OOPS) or possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9.
local
low complexity
linux CWE-416
7.1
2020-01-27 CVE-2019-20422 Improper Handling of Exceptional Conditions vulnerability in Linux Kernel
In the Linux kernel before 5.3.4, fib6_rule_lookup in net/ipv6/ip6_fib.c mishandles the RT6_LOOKUP_F_DST_NOREF flag in a reference-count decision, leading to (for example) a crash that was identified by syzkaller, aka CID-7b09c2d052db.
local
low complexity
linux CWE-755
5.5
2020-01-22 CVE-2018-16268 Improper Privilege Management vulnerability in Linux Tizen
The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actions, due to improper D-Bus security policy configurations.
low complexity
linux CWE-269
4.3
2020-01-22 CVE-2018-16267 Improper Privilege Management vulnerability in Linux Tizen
The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions, due to improper D-Bus security policy configurations.
low complexity
linux CWE-269
8.1
2020-01-22 CVE-2018-16266 Improper Privilege Management vulnerability in Linux Tizen
The Enlightenment system service in Tizen allows an unprivileged process to fully control or capture windows, due to improper D-Bus security policy configurations.
low complexity
linux CWE-269
8.1
2020-01-22 CVE-2018-16265 Improper Privilege Management vulnerability in Linux Tizen
The bt/bt_core system service in Tizen allows an unprivileged process to create a system user interface and control the Bluetooth pairing process, due to improper D-Bus security policy configurations.
low complexity
linux CWE-269
6.5
2020-01-22 CVE-2018-16264 Information Exposure vulnerability in Linux Tizen
The BlueZ system service in Tizen allows an unprivileged process to partially control Bluetooth or acquire sensitive information, due to improper D-Bus security policy configurations.
low complexity
linux CWE-200
6.5
2020-01-22 CVE-2018-16263 Improper Privilege Management vulnerability in Linux Tizen
The PulseAudio system service in Tizen allows an unprivileged process to control its A2DP MediaEndpoint, due to improper D-Bus security policy configurations.
low complexity
linux CWE-269
8.8