Vulnerability Name:

CVE-2015-9004 (CCN-127978)

Assigned:2017-05-01
Published:2017-05-01
Updated:2023-01-19
Summary:
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2015-9004

Source: security@android.com
Type: Issue Tracking, Patch, Third Party Advisory
security@android.com

Source: CCN
Type: BID-98166
Google Android Kernel Performance Subsystem CVE-2015-9004 Privilege Escalation Vulnerability

Source: security@android.com
Type: Third Party Advisory, VDB Entry
security@android.com

Source: XF
Type: UNKNOWN
linux-kernel-cve20159004-priv-esc(127978)

Source: CCN
Type: Linux Kernel GIT Repository
perf: Tighten (and fix) the grouping condition

Source: security@android.com
Type: Issue Tracking, Patch, Third Party Advisory
security@android.com

Source: CCN
Type: Android Open Source Project
Android Security Bulletin—May 2017

Source: security@android.com
Type: Vendor Advisory
security@android.com

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/o:linux:linux_kernel:3.18:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20159004
    V
    CVE-2015-9004
    2022-05-20
    oval:org.opensuse.security:def:40778
    P
    Security update for postgresql10 (Important)
    2021-11-17
    oval:org.opensuse.security:def:14204
    P
    libXv1-1.0.10-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14136
    P
    freeradius-server-3.0.14-1.8 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14842
    P
    bash-4.3-83.23.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13844
    P
    gvim-7.4.326-2.14 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14864
    P
    cups-pk-helper-0.2.5-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13866
    P
    libQt5Concurrent5-5.6.1-11.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13934
    P
    libnghttp2-14-1.7.1-1.84 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13836
    P
    gnutls-3.2.15-11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13981
    P
    logrotate-3.8.7-3.14 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13999
    P
    pam_ssh-2.0-1.39 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14180
    P
    kernel-default-4.4.73-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14018
    P
    python-pyOpenSSL-16.0.0-2.3.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14191
    P
    libXRes1-1.0.7-3.53 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14111
    P
    cups-1.7.5-19.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:38660
    P
    Security update for MozillaFirefox (Important)
    2021-07-16
    oval:org.opensuse.security:def:38076
    P
    Security update for arpwatch (Important)
    2021-06-28
    oval:org.opensuse.security:def:42049
    P
    sysstat-8.1.5-7.9.56 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:42004
    P
    libpoppler-glib4-0.12.3-1.2.44 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:40425
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:19181
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37843
    P
    libQt5Concurrent5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18978
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38177
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40517
    P
    Security update for clamav (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:19193
    P
    Security update for libpng16 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38593
    P
    fontconfig on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:19090
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:38235
    P
    krb5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40669
    P
    Recommended update for ucode-intel (Important)
    2020-12-01
    oval:org.opensuse.security:def:19217
    P
    Security update for evolution (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38632
    P
    libFLAC++6 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40413
    P
    Security update for smt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:19123
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:38325
    P
    libmodplug1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:19855
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:18727
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:41241
    P
    Security update for the Linux Kernel (Live Patch 26 for SLE 12 SP3) (Important)
    2020-12-01
    oval:org.opensuse.security:def:38485
    P
    squashfs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40847
    P
    Security update for openssh (Important)
    2020-12-01
    oval:org.opensuse.security:def:19881
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:38704
    P
    libnghttp2-14 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18762
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:41286
    P
    Security update for the Linux Kernel (Live Patch 20 for SLE 12 SP3) (Important)
    2020-12-01
    oval:org.opensuse.security:def:37844
    P
    libQt5WebKit5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38544
    P
    apache2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40949
    P
    Security update for the Linux Kernel (Live Patch 32 for SLE 12 SP2) (Important)
    2020-12-01
    oval:org.opensuse.security:def:39342
    P
    Security update for python-PyYAML (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18848
    P
    Security update for openwsman (Important)
    2020-12-01
    oval:org.opensuse.security:def:41315
    P
    Security update for the Linux Kernel (Live Patch 23 for SLE 12 SP3) (Important)
    2020-12-01
    oval:org.opensuse.security:def:37855
    P
    libXinerama1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18719
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:41125
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP2) (Important)
    2020-12-01
    oval:org.opensuse.security:def:39384
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:18906
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:41366
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:37939
    P
    libplist3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40414
    P
    Security update for atftp (Important)
    2020-12-01
    oval:org.opensuse.security:def:41189
    P
    Security update for ovmf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18940
    P
    Security update for gnome-shell (Moderate)
    2020-12-01
    oval:com.ubuntu.precise:def:20159004000
    V
    CVE-2015-9004 on Ubuntu 12.04 LTS (precise) - medium.
    2017-05-02
    oval:com.ubuntu.xenial:def:201590040000000
    V
    CVE-2015-9004 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-05-02
    oval:com.ubuntu.trusty:def:20159004000
    V
    CVE-2015-9004 on Ubuntu 14.04 LTS (trusty) - medium.
    2017-05-02
    oval:com.ubuntu.xenial:def:20159004000
    V
    CVE-2015-9004 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-05-02
    BACK
    linux linux kernel 3.18