|
266001
|
7.5 |
HIGH
Network
|
oracle canonical linux
|
vm_server ubuntu_linux linux_kernel
|
The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive informa…
|
CWE-200
Information Exposure
|
CVE-2016-2117
|
2024-11-21 11:47 |
2016-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266002
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
The tcp_cwnd_reduction function in net/ipv4/tcp_input.c in the Linux kernel before 4.3.5 allows remote attackers to cause a denial of service (divide-by-zero error and system crash) via crafted TCP t…
|
CWE-189
Numeric Errors
|
CVE-2016-2070
|
2024-11-21 11:47 |
2016-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266003
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The asn1_ber_decoder function in lib/asn1_decoder.c in the Linux kernel before 4.3 allows attackers to cause a denial of service (panic) via an ASN.1 BER file that lacks a public key, leading to mish…
|
CWE-310
Cryptographic Issues
|
CVE-2016-2053
|
2024-11-21 11:47 |
2016-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266004
|
4.6 |
MEDIUM
Physics
|
canonical linux novell
|
ubuntu_linux linux_kernel suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_real_time_extension su…
|
The ati_remote2_probe function in drivers/input/misc/ati_remote2.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and sy…
|
NVD-CWE-Other
|
CVE-2016-2185
|
2024-11-21 11:47 |
2016-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266005
|
4.6 |
MEDIUM
Physics
|
linux canonical novell
|
linux_kernel ubuntu_linux suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_real_time_extension su…
|
The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL poin…
|
NVD-CWE-Other
|
CVE-2016-2184
|
2024-11-21 11:47 |
2016-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266006
|
7.8 |
HIGH
Local
|
linux debian redhat oracle
|
linux_kernel debian_linux enterprise_linux linux
|
The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, which allows local users to cause a denial of service (system crash) or possibl…
|
CWE-20
Improper Input Validation
|
CVE-2016-2143
|
2024-11-21 11:47 |
2016-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266007
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy data, which makes it easier for local users to forge MAC values via a timing si…
|
CWE-19
Data Processing Errors
|
CVE-2016-2085
|
2024-11-21 11:47 |
2016-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266008
|
7.4 |
HIGH
Local
|
canonical linux
|
ubuntu_linux linux_kernel
|
Race condition in arch/x86/mm/tlb.c in the Linux kernel before 4.4.1 allows local users to gain privileges by triggering access to a paging structure by a different CPU.
|
CWE-362
Race Condition
|
CVE-2016-2069
|
2024-11-21 11:47 |
2016-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266009
|
5.9 |
MEDIUM
Network
|
canonical samba
|
ubuntu_linux samba
|
Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB c…
|
CWE-254
7PK - Security Features
|
CVE-2016-2115
|
2024-11-21 11:47 |
2016-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266010
|
5.9 |
MEDIUM
Network
|
samba canonical
|
samba ubuntu_linux
|
The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle att…
|
CWE-254
7PK - Security Features
|
CVE-2016-2114
|
2024-11-21 11:47 |
2016-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|