cbcvebase.
CVE-2018-3665
published 2018-06-21

CVE-2018-3665: System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data…

PriorityP424medium5.6CVSS 3.1
AVLACHPRLUINSCCHINAN
EPSS
0.61%
45.3th percentile
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.

Affected

503 ranges· showing 25
VendorProductVersion rangeFixed in
applemacos_high_sierra_10.13.6_security_update_2018-004_sierra_security_update_2018-0
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
citrixcitrix_adm
citrixcitrix_hypervisor
citrixcitrix_virtual_apps_and_desktops
citrixendpoint_management
citrixnetscaler_adc
citrixnetscaler_gateway
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
debiandebian_linux
debiandebian_linux
debianlinux< linux 4.6.1-1 (bookworm)linux 4.6.1-1 (bookworm)
debianxen< linux 4.6.1-1 (bookworm)linux 4.6.1-1 (bookworm)
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
intelcore_i3
intelcore_i3

CVSS provenance

nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.