CVEs (91)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
8Canonical DebianLinux+5 more12Debian Linux Enterprise MrgEvergreen+9 moreMay 6, 2026 Nov 10, 2014 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks tha...Show more |
11Apple DebianFedoraproject+8 more20Aix DatabaseDebian Linux+17 moreMay 28, 2026 Oct 15, 2014 N/A· v4 3.4 LOW· v3 4.3 MEDIUM· v2 The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a...Show more |
3Canonical LinuxNovell3Linux Kernel Suse Linux Enterprise ServerUbuntu LinuxMay 6, 2026 Oct 13, 2014 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree...Show more |
2Linux Novell2Linux Kernel Suse Linux Enterprise ServerMay 6, 2026 Sep 28, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system c...Show more |
3Libguestfs NovellSuse3Libguestfs Suse Linux Enterprise ServerSuse Linux Enterprise Software Development KitApr 29, 2026 Nov 5, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this d...Show more |
4Canonical NovellPuppet+1 more6Puppet PuppetPuppet Enterprise+3 moreApr 29, 2026 Aug 19, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a cra...Show more |
2Linux Novell2Linux Kernel Suse Linux Enterprise ServerApr 29, 2026 Jun 21, 2012 N/A· v4 N/A· v3 6.4 MEDIUM· v2 The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of data sent, which might allow remote attackers to obtain sensitive infor...Show more |
2Linux Novell2Linux Kernel Suse Linux Enterprise ServerApr 29, 2026 Jun 21, 2012 N/A· v4 N/A· v3 7.8 HIGH· v2 The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of serv...Show more |
3Linux NovellRedhat8Enterprise Linux Enterprise Linux DesktopEnterprise Linux Eus+5 moreApr 29, 2026 Jun 13, 2012 N/A· v4 N/A· v3 1.2 LOW· v2 The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl...Show more |
1Novell 1Suse Linux Enterprise Server Apr 23, 2026 Sep 18, 2009 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Unspecified vulnerability in ia32el (aka the IA 32 emulation functionality) before 7042_7022-0.4.2 in SUSE Linux Enterprise (SLE) 10 SP2 on Itanium IA64 machines allows local users to cause a denial of service (system cr...Show more |
5Canonical DebianLinux+2 more6Debian Linux Linux KernelOpensuse+3 moreApr 23, 2026 Jul 9, 2008 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service b...Show more |