Vulnerabilities > Linux > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-05-22 CVE-2017-9150 Information Exposure vulnerability in Linux Kernel
The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value available for restricting the output of the print_bpf_insn function, which allows local users to obtain sensitive address information via crafted bpf system calls.
local
low complexity
linux CWE-200
5.5
2017-05-18 CVE-2017-9059 Improper Resource Shutdown or Release vulnerability in Linux Kernel
The NFSv4 implementation in the Linux kernel through 4.11.1 allows local users to cause a denial of service (resource consumption) by leveraging improper channel callback shutdown when unmounting an NFSv4 filesystem, aka a "module reference and kernel daemon" leak.
local
low complexity
linux CWE-404
5.5
2017-05-15 CVE-2017-7495 Information Exposure vulnerability in Linux Kernel
fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-before-commit list, which allows local users to obtain sensitive information from other users' files in opportunistic circumstances by waiting for a hardware reset, creating a new file, making write system calls, and reading this file.
local
low complexity
linux CWE-200
5.5
2017-05-12 CVE-2017-8925 Improper Resource Shutdown or Release vulnerability in multiple products
The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows local users to cause a denial of service (tty exhaustion) by leveraging reference count mishandling.
local
low complexity
linux debian CWE-404
5.5
2017-05-12 CVE-2017-8924 Integer Underflow (Wrap or Wraparound) vulnerability in multiple products
The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel before 4.10.4 allows local users to obtain sensitive information (in the dmesg ringbuffer and syslog) from uninitialized kernel memory by using a crafted USB device (posing as an io_ti USB serial device) to trigger an integer underflow.
low complexity
linux debian CWE-191
4.6
2017-05-12 CVE-2017-0634 Information Exposure vulnerability in Linux Kernel 3.18
An information disclosure vulnerability in the Synaptics touchscreen driver could enable a local malicious application to access data outside of its permission levels.
local
high complexity
linux CWE-200
4.7
2017-05-12 CVE-2017-0633 Information Exposure vulnerability in Linux Kernel 3.10/3.18
An information disclosure vulnerability in the Broadcom Wi-Fi driver could enable a local malicious component to access data outside of its permission levels.
local
high complexity
linux CWE-200
4.7
2017-05-12 CVE-2017-0632 Information Exposure vulnerability in Linux Kernel 3.10
An information disclosure vulnerability in the Qualcomm sound codec driver could enable a local malicious application to access data outside of its permission levels.
local
high complexity
linux CWE-200
4.7
2017-05-12 CVE-2017-0631 Information Exposure vulnerability in Linux Kernel 3.10/3.18
An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels.
local
high complexity
linux CWE-200
4.7
2017-05-12 CVE-2017-0630 Information Exposure vulnerability in Linux Kernel 3.10/3.18
An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permission levels.
local
high complexity
linux CWE-200
4.7