NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 36323 | CVE-2014-9731 | The UDF filesystem implementation in the Linux kernel before 3.18.2 does not ensure that space is available for storing a symlink target's name along with a trailing character, which allows local users to obtain sensitive information via a crafted filesystem image, related to fs/udf/symlink.c and fs/udf/unicode.c. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-12 | View | |
| 36320 | CVE-2014-9728 | The UDF filesystem implementation in the Linux kernel before 3.18.2 does not validate certain lengths, which allows local users to cause a denial of service (buffer over-read and system crash) via a crafted filesystem image, related to fs/udf/inode.c and fs/udf/symlink.c. | 2 | 4.9 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 85518 | CVE-2017-8305 | The UDFclient (before 0.8.8) custom strlcpy implementation has a buffer overflow. UDFclient's strlcpy is used only on systems with a C library (e.g., glibc) that lacks its own strlcpy. | 2 | 7.5 | High | 2017-05-27 | 2017-05-09 | View | |
| 47229 | CVE-2012-6548 | The udf_encode_fh function in fs/udf/namei.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted application. | 2 | 1.9 | Low | 2017-01-19 | 2014-02-06 | View | |
| 36322 | CVE-2014-9730 | The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18.2 relies on component lengths that are unused, which allows local users to cause a denial of service (system crash) via a crafted UDF filesystem image. | 2 | 4.9 | Medium | 2017-01-19 | 2016-12-21 | View |
Page 14809 of 17672, showing 5 records out of 88360 total, starting on record 74041, ending on 74045