Количество 58
Количество 58

CVE-2015-2150
Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.
CVE-2015-2150
Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not pro ...
GHSA-w7jv-fgrf-v497
Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.

SUSE-SU-2015:0658-1
Security Update for Linux Kernel
ELSA-2015-3036
ELSA-2015-3036: Unbreakable Enterprise kernel security and bugfix update (IMPORTANT)
ELSA-2015-3035
ELSA-2015-3035: Unbreakable Enterprise kernel security and bugfix update (IMPORTANT)

SUSE-SU-2015:1376-1
Security update for Linux kernel

SUSE-SU-2015:0736-1
Security update for Linux kernel

SUSE-SU-2015:1174-1
Security update for Linux kernel

SUSE-SU-2015:0581-1
Security update for Linux kernel

SUSE-RU-2015:0621-1
Security update for Linux kernel

CVE-2015-1421
Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.

CVE-2015-1421
Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.

CVE-2015-1421
Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.
CVE-2015-1421
Use-after-free vulnerability in the sctp_assoc_update function in net/ ...

CVE-2014-8159
The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.

CVE-2014-8159
The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.

CVE-2014-8159
The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.
CVE-2014-8159
The InfiniBand (IB) implementation in the Linux kernel package before ...

SUSE-SU-2015:0832-1
Security update for kgraft-patch-SLE12_Update_1, kgraft-patch-SLE12_Update_2
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2015-2150 Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response. | CVSS2: 4.9 | 0% Низкий | больше 10 лет назад |
CVE-2015-2150 Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not pro ... | CVSS2: 4.9 | 0% Низкий | больше 10 лет назад | |
GHSA-w7jv-fgrf-v497 Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response. | 0% Низкий | около 3 лет назад | ||
![]() | SUSE-SU-2015:0658-1 Security Update for Linux Kernel | больше 10 лет назад | ||
ELSA-2015-3036 ELSA-2015-3036: Unbreakable Enterprise kernel security and bugfix update (IMPORTANT) | около 10 лет назад | |||
ELSA-2015-3035 ELSA-2015-3035: Unbreakable Enterprise kernel security and bugfix update (IMPORTANT) | около 10 лет назад | |||
![]() | SUSE-SU-2015:1376-1 Security update for Linux kernel | почти 11 лет назад | ||
![]() | SUSE-SU-2015:0736-1 Security update for Linux kernel | почти 11 лет назад | ||
![]() | SUSE-SU-2015:1174-1 Security update for Linux kernel | почти 11 лет назад | ||
![]() | SUSE-SU-2015:0581-1 Security update for Linux kernel | почти 11 лет назад | ||
![]() | SUSE-RU-2015:0621-1 Security update for Linux kernel | почти 11 лет назад | ||
![]() | CVE-2015-1421 Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data. | CVSS2: 10 | 26% Средний | больше 10 лет назад |
![]() | CVE-2015-1421 Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data. | CVSS2: 7.1 | 26% Средний | больше 10 лет назад |
![]() | CVE-2015-1421 Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data. | CVSS2: 10 | 26% Средний | больше 10 лет назад |
CVE-2015-1421 Use-after-free vulnerability in the sctp_assoc_update function in net/ ... | CVSS2: 10 | 26% Средний | больше 10 лет назад | |
![]() | CVE-2014-8159 The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/. | CVSS2: 6.9 | 0% Низкий | больше 10 лет назад |
![]() | CVE-2014-8159 The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/. | CVSS2: 6.2 | 0% Низкий | больше 10 лет назад |
![]() | CVE-2014-8159 The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/. | CVSS2: 6.9 | 0% Низкий | больше 10 лет назад |
CVE-2014-8159 The InfiniBand (IB) implementation in the Linux kernel package before ... | CVSS2: 6.9 | 0% Низкий | больше 10 лет назад | |
![]() | SUSE-SU-2015:0832-1 Security update for kgraft-patch-SLE12_Update_1, kgraft-patch-SLE12_Update_2 | 26% Средний | больше 10 лет назад |
Уязвимостей на страницу