CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:C/I:C/A:C
AI Score
Confidence
High
EPSS
Percentile
99.0%
Matthew Daley reported an information leak in the floppy disk driver of the
Linux kernel. An unprivileged local user could exploit this flaw to obtain
potentially sensitive information from kernel memory. (CVE-2014-1738)
Matthew Daley reported a flaw in the handling of ioctl commands by the
floppy disk driver in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges if the floppy disk
module is loaded. (CVE-2014-1737)
A flaw was discovered in the vhost-net subsystem of the Linux kernel. Guest
OS users could exploit this flaw to cause a denial of service (host OS
crash). (CVE-2014-0055)
A flaw was discovered in the handling of network packets when mergeable
buffers are disabled for virtual machines in the Linux kernel. Guest OS
users may exploit this flaw to cause a denial of service (host OS crash) or
possibly gain privilege on the host OS. (CVE-2014-0077)
A flaw was discovered in the Linux kernel’s handling of the SCTP handshake.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2014-0101)
A flaw was discovered in the handling of routing information in Linux
kernel’s IPv6 stack. A remote attacker could exploit this flaw to cause a
denial of service (memory consumption) via a flood of ICMPv6 router
advertisement packets. (CVE-2014-2309)
An error was discovered in the Linux kernel’s DCCP protocol support. A
remote attacked could exploit this flaw to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2014-2523)
Max Sydorenko discovered a race condition in the Atheros 9k wireless driver
in the Linux kernel. This race could be exploited by remote attackers to
cause a denial of service (system crash). (CVE-2014-2672)
An error was discovered in the Reliable Datagram Sockets (RDS) protocol
stack in the Linux kernel. A local user could exploit this flaw to cause a
denial of service (system crash) or possibly have unspecified other impact.
(CVE-2014-2678)
Yaara Rozenblum discovered a race condition in the Linux kernel’s Generic
IEEE 802.11 Networking Stack (mac80211). Remote attackers could exploit
this flaw to cause a denial of service (system crash). (CVE-2014-2706)
A flaw was discovered in the Linux kernel’s ping sockets. An unprivileged
local user could exploit this flaw to cause a denial of service (system
crash) or possibly gain privileges via a crafted application.
(CVE-2014-2851)
Sasha Levin reported a bug in the Linux kernel’s virtual memory management
subsystem. An unprivileged local user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-3122)
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Ubuntu | 12.04 | noarch | linux-image-3.8.0-41-generic | < 3.8.0-41.60~precise1 | UNKNOWN |
Ubuntu | 12.04 | noarch | block-modules-3.8.0-41-generic-di | < 3.8.0-41.60~precise1 | UNKNOWN |
Ubuntu | 12.04 | noarch | crypto-modules-3.8.0-41-generic-di | < 3.8.0-41.60~precise1 | UNKNOWN |
Ubuntu | 12.04 | noarch | fat-modules-3.8.0-41-generic-di | < 3.8.0-41.60~precise1 | UNKNOWN |
Ubuntu | 12.04 | noarch | fb-modules-3.8.0-41-generic-di | < 3.8.0-41.60~precise1 | UNKNOWN |
Ubuntu | 12.04 | noarch | firewire-core-modules-3.8.0-41-generic-di | < 3.8.0-41.60~precise1 | UNKNOWN |
Ubuntu | 12.04 | noarch | floppy-modules-3.8.0-41-generic-di | < 3.8.0-41.60~precise1 | UNKNOWN |
Ubuntu | 12.04 | noarch | fs-core-modules-3.8.0-41-generic-di | < 3.8.0-41.60~precise1 | UNKNOWN |
Ubuntu | 12.04 | noarch | fs-secondary-modules-3.8.0-41-generic-di | < 3.8.0-41.60~precise1 | UNKNOWN |
Ubuntu | 12.04 | noarch | input-modules-3.8.0-41-generic-di | < 3.8.0-41.60~precise1 | UNKNOWN |
ubuntu.com/security/CVE-2014-0055
ubuntu.com/security/CVE-2014-0077
ubuntu.com/security/CVE-2014-0101
ubuntu.com/security/CVE-2014-1737
ubuntu.com/security/CVE-2014-1738
ubuntu.com/security/CVE-2014-2309
ubuntu.com/security/CVE-2014-2523
ubuntu.com/security/CVE-2014-2672
ubuntu.com/security/CVE-2014-2678
ubuntu.com/security/CVE-2014-2706
ubuntu.com/security/CVE-2014-2851
ubuntu.com/security/CVE-2014-3122