VYPR

rpm package

suse/kernel-bigmem&distro=SUSE Linux Enterprise Server for SAP Applications 11 SP4

pkg:rpm/suse/kernel-bigmem&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4

Vulnerabilities (189)

  • CVE-2017-15115HigNov 15, 2017
    affected < 3.0.101-108.21.1fixed 3.0.101-108.21.1

    The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other imp

  • CVE-2017-15102MedNov 15, 2017
    affected < 3.0.101-108.18.1fixed 3.0.101-108.18.1

    The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occurs after a race condition and a

  • CVE-2017-16649MedNov 7, 2017
    affected < 3.0.101-108.18.1fixed 3.0.101-108.18.1

    The usbnet_generic_cdc_bind function in drivers/net/usb/cdc_ether.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (divide-by-zero error and system crash) or possibly have unspecified other impact via a crafted USB device.

  • CVE-2017-16644MedNov 7, 2017
    affected < 3.0.101-108.38.1fixed 3.0.101-108.38.1

    The hdpvr_probe function in drivers/media/usb/hdpvr/hdpvr-core.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (improper error handling and system crash) or possibly have unspecified other impact via a crafted USB device.

  • CVE-2017-16538MedNov 4, 2017
    affected < 3.0.101-108.21.1fixed 3.0.101-108.21.1

    drivers/media/usb/dvb-usb-v2/lmedm04.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafted USB device, related to a missing warm-start check and inc

  • CVE-2017-16537MedNov 4, 2017
    affected < 3.0.101-108.18.1fixed 3.0.101-108.18.1

    The imon_probe function in drivers/media/rc/imon.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB device.

  • CVE-2017-16536MedNov 4, 2017
    affected < 3.0.101-108.18.1fixed 3.0.101-108.18.1

    The cx231xx_usb_probe function in drivers/media/usb/cx231xx/cx231xx-cards.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB device.

  • CVE-2017-16535MedNov 4, 2017
    affected < 3.0.101-108.18.1fixed 3.0.101-108.18.1

    The usb_get_bos_descriptor function in drivers/usb/core/config.c in the Linux kernel before 4.13.10 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.

  • CVE-2017-16534MedNov 4, 2017
    affected < 3.0.101-108.21.1fixed 3.0.101-108.21.1

    The cdc_parse_cdc_header function in drivers/usb/core/message.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.

  • CVE-2017-16533MedNov 4, 2017
    affected < 3.0.101-108.81.1fixed 3.0.101-108.81.1

    The usbhid_parse function in drivers/hid/usbhid/hid-core.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.

  • CVE-2017-16531MedNov 4, 2017
    affected < 3.0.101-108.18.1fixed 3.0.101-108.18.1

    drivers/usb/core/config.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device, related to the USB_DT_INTERFACE_ASSOCIATION descriptor.

  • CVE-2017-16529MedNov 4, 2017
    affected < 3.0.101-108.18.1fixed 3.0.101-108.18.1

    The snd_usb_create_streams function in sound/usb/card.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.

  • CVE-2017-16527MedNov 4, 2017
    affected < 3.0.101-108.18.1fixed 3.0.101-108.18.1

    sound/usb/mixer.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (snd_usb_mixer_interrupt use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device.

  • CVE-2017-16525MedNov 4, 2017
    affected < 3.0.101-108.18.1fixed 3.0.101-108.18.1

    The usb_serial_console_disconnect function in drivers/usb/serial/console.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device, related to disconnect

  • CVE-2017-13080MedOct 17, 2017
    affected < 3.0.101-108.18.1fixed 3.0.101-108.18.1

    Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.

  • CVE-2017-15265HigOct 16, 2017
    affected < 3.0.101-108.18.1fixed 3.0.101-108.18.1

    Race condition in the ALSA subsystem in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted /dev/snd/seq ioctl calls, related to sound/core/seq/seq_clientmgr.c and sound/core/seq/seq

  • CVE-2017-15274MedOct 12, 2017
    affected < 3.0.101-108.18.1fixed 3.0.101-108.18.1

    security/keys/keyctl.c in the Linux kernel before 4.11.5 does not consider the case of a NULL payload in conjunction with a nonzero length value, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted add_key or keyctl system call,

  • CVE-2017-1000253HigKEVOct 5, 2017
    affected < 3.0.101-108.13.1fixed 3.0.101-108.13.1

    Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backpo

  • CVE-2017-1000112HigOct 5, 2017
    affected < 3.0.101-108.18.1fixed 3.0.101-108.18.1

    Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE __ip_append_data() calls ip_ufo_append_data() to append. However in between two send() calls, the append path can be switched from UFO to non-UFO one, which lea

  • CVE-2017-14340MedSep 15, 2017
    affected < 3.0.101-108.18.1fixed 3.0.101-108.18.1

    The XFS_IS_REALTIME_INODE macro in fs/xfs/xfs_linux.h in the Linux kernel before 4.13.2 does not verify that a filesystem has a realtime device, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via vectors related to setting an RHINHERIT f

Page 5 of 10