CVE-2016-3949 (simatic_s7-300_with_profitnet_support_firmware, simatic_s7-300_without_profitnet_support_firmware)

CVE-2016-3949 (simatic_s7-300_with_profitnet_support_firmware, simatic_s7-300_without_profitnet_support_firmware)

Siemens SIMATIC S7-300 Profinet-enabled CPU devices with firmware before 3.2.12 and SIMATIC S7-300 Profinet-disabled CPU devices with firmware before 3.3.12 allow remote attackers to cause a denial of service (defect-mode transition) via crafted (1) ISO-TSAP or (2) Profibus packets.

Source: CVE-2016-3949 (simatic_s7-300_with_profitnet_support_firmware, simatic_s7-300_without_profitnet_support_firmware)

CVE-2016-3707 (linux_kernel-rt)

CVE-2016-3707 (linux_kernel-rt)

The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before 3.10.0-327.22.1 in Red Hat Enterprise Linux for Real Time 7 and other products, allows remote attackers to execute SysRq commands via crafted ICMP Echo Request packets, as demonstrated by a brute-force attack to discover a cookie, or an attack that occurs after reading the local icmp_echo_sysrq file.

Source: CVE-2016-3707 (linux_kernel-rt)

CVE-2014-9904 (linux_kernel)

CVE-2014-9904 (linux_kernel)

The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.17 does not properly check for an integer overflow, which allows local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call.

Source: CVE-2014-9904 (linux_kernel)