Логотип exploitDog
bind:"CVE-2014-8159" OR bind:"CVE-2015-1421" OR bind:"CVE-2015-2150"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2014-8159" OR bind:"CVE-2015-1421" OR bind:"CVE-2015-2150"

Количество 58

Количество 58

nvd логотип

CVE-2014-8159

больше 10 лет назад

The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.

CVSS2: 6.9
EPSS: Низкий
debian логотип

CVE-2014-8159

больше 10 лет назад

The InfiniBand (IB) implementation in the Linux kernel package before ...

CVSS2: 6.9
EPSS: Низкий
github логотип

GHSA-355g-wjmx-fcfq

около 3 лет назад

The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.

EPSS: Низкий
oracle-oval логотип

ELSA-2015-0783

больше 10 лет назад

ELSA-2015-0783: kernel security and bug fix update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2015-0783-1

больше 10 лет назад

ELSA-2015-0783-1: kernel security and bug fix update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2015-2150

больше 10 лет назад

Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.

CVSS2: 4.9
EPSS: Низкий
redhat логотип

CVE-2015-2150

больше 10 лет назад

Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.

CVSS2: 5.2
EPSS: Низкий
nvd логотип

CVE-2015-2150

больше 10 лет назад

Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.

CVSS2: 4.9
EPSS: Низкий
debian логотип

CVE-2015-2150

больше 10 лет назад

Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not pro ...

CVSS2: 4.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:1376-1

почти 11 лет назад

Security update for Linux kernel

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:0736-1

почти 11 лет назад

Security update for Linux kernel

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:1174-1

почти 11 лет назад

Security update for Linux kernel

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:0581-1

почти 11 лет назад

Security update for Linux kernel

EPSS: Низкий
suse-cvrf логотип

SUSE-RU-2015:0621-1

почти 11 лет назад

Security update for Linux kernel

EPSS: Низкий
ubuntu логотип

CVE-2015-1421

больше 10 лет назад

Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.

CVSS2: 10
EPSS: Средний
redhat логотип

CVE-2015-1421

больше 10 лет назад

Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.

CVSS2: 7.1
EPSS: Средний
nvd логотип

CVE-2015-1421

больше 10 лет назад

Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2015-1421

больше 10 лет назад

Use-after-free vulnerability in the sctp_assoc_update function in net/ ...

CVSS2: 10
EPSS: Средний
oracle-oval логотип

ELSA-2015-0674

больше 10 лет назад

ELSA-2015-0674: kernel security and bug fix update (IMPORTANT)

EPSS: Низкий
github логотип

GHSA-w7jv-fgrf-v497

около 3 лет назад

Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2014-8159

The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.

CVSS2: 6.9
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-8159

The InfiniBand (IB) implementation in the Linux kernel package before ...

CVSS2: 6.9
0%
Низкий
больше 10 лет назад
github логотип
GHSA-355g-wjmx-fcfq

The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.

0%
Низкий
около 3 лет назад
oracle-oval логотип
ELSA-2015-0783

ELSA-2015-0783: kernel security and bug fix update (IMPORTANT)

больше 10 лет назад
oracle-oval логотип
ELSA-2015-0783-1

ELSA-2015-0783-1: kernel security and bug fix update (IMPORTANT)

больше 10 лет назад
ubuntu логотип
CVE-2015-2150

Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.

CVSS2: 4.9
0%
Низкий
больше 10 лет назад
redhat логотип
CVE-2015-2150

Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.

CVSS2: 5.2
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-2150

Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.

CVSS2: 4.9
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-2150

Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not pro ...

CVSS2: 4.9
0%
Низкий
больше 10 лет назад
suse-cvrf логотип
SUSE-SU-2015:1376-1

Security update for Linux kernel

почти 11 лет назад
suse-cvrf логотип
SUSE-SU-2015:0736-1

Security update for Linux kernel

почти 11 лет назад
suse-cvrf логотип
SUSE-SU-2015:1174-1

Security update for Linux kernel

почти 11 лет назад
suse-cvrf логотип
SUSE-SU-2015:0581-1

Security update for Linux kernel

почти 11 лет назад
suse-cvrf логотип
SUSE-RU-2015:0621-1

Security update for Linux kernel

почти 11 лет назад
ubuntu логотип
CVE-2015-1421

Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.

CVSS2: 10
26%
Средний
больше 10 лет назад
redhat логотип
CVE-2015-1421

Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.

CVSS2: 7.1
26%
Средний
больше 10 лет назад
nvd логотип
CVE-2015-1421

Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.

CVSS2: 10
26%
Средний
больше 10 лет назад
debian логотип
CVE-2015-1421

Use-after-free vulnerability in the sctp_assoc_update function in net/ ...

CVSS2: 10
26%
Средний
больше 10 лет назад
oracle-oval логотип
ELSA-2015-0674

ELSA-2015-0674: kernel security and bug fix update (IMPORTANT)

больше 10 лет назад
github логотип
GHSA-w7jv-fgrf-v497

Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.

0%
Низкий
около 3 лет назад

Уязвимостей на страницу