Show filters
187 Total Results
Displaying 101-110 of 187
Sort by:
Attacker Value
Unknown

CVE-2006-0038

Disclosure Date: March 22, 2006 (last updated February 22, 2025)
Integer overflow in the do_replace function in netfilter for Linux before 2.6.16-rc3, when using "virtualization solutions" such as OpenVZ, allows local users with CAP_NET_ADMIN rights to cause a buffer overflow in the copy_from_user function.
0
Attacker Value
Unknown

CVE-2006-1242

Disclosure Date: March 15, 2006 (last updated February 22, 2025)
The ip_push_pending_frames function in Linux 2.4.x and 2.6.x before 2.6.16 increments the IP ID field when sending a RST after receiving unsolicited TCP SYN-ACK packets, which allows remote attackers to conduct an Idle Scan (nmap -sI) attack, which bypasses intended protections against such attacks.
0
Attacker Value
Unknown

CVE-2006-0457

Disclosure Date: March 14, 2006 (last updated February 22, 2025)
Race condition in the (1) add_key, (2) request_key, and (3) keyctl functions in Linux kernel 2.6.x allows local users to cause a denial of service (crash) or read sensitive kernel memory by modifying the length of a string argument between the time that the kernel calculates the length and when it copies the data into kernel memory.
0
Attacker Value
Unknown

CVE-2006-0557

Disclosure Date: March 12, 2006 (last updated February 22, 2025)
sys_mbind in mempolicy.c in Linux kernel 2.6.16 and earlier does not sanity check the maxnod variable before making certain computations for the get_nodes function, which has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2006-0742

Disclosure Date: March 09, 2006 (last updated February 22, 2025)
The die_if_kernel function in arch/ia64/kernel/unaligned.c in Linux kernel 2.6.x before 2.6.15.6, possibly when compiled with certain versions of gcc, has the "noreturn" attribute set, which allows local users to cause a denial of service by causing user faults on Itanium systems.
0
Attacker Value
Unknown

CVE-2006-0555

Disclosure Date: March 07, 2006 (last updated February 22, 2025)
The Linux Kernel before 2.6.15.5 allows local users to cause a denial of service (NFS client panic) via unknown attack vectors related to the use of O_DIRECT (direct I/O).
0
Attacker Value
Unknown

CVE-2006-0554

Disclosure Date: March 07, 2006 (last updated February 22, 2025)
Linux kernel 2.6 before 2.6.15.5 allows local users to obtain sensitive information via a crafted XFS ftruncate call, which may return stale data.
0
Attacker Value
Unknown

CVE-2006-0741

Disclosure Date: March 07, 2006 (last updated February 22, 2025)
Linux kernel before 2.6.15.5, when running on Intel processors, allows local users to cause a denial of service ("endless recursive fault") via unknown attack vectors related to a "bad elf entry address."
0
Attacker Value
Unknown

CVE-2006-0482

Disclosure Date: January 31, 2006 (last updated February 22, 2025)
Linux kernel 2.6.15.1 and earlier, when running on SPARC architectures, allows local users to cause a denial of service (hang) via a "date -s" command, which causes invalid sign extended arguments to be provided to the get_compat_timespec function call.
0
Attacker Value
Unknown

CVE-2006-0096

Disclosure Date: January 06, 2006 (last updated February 22, 2025)
wan/sdla.c in Linux kernel 2.6.x before 2.6.11 and 2.4.x before 2.4.29 does not require the CAP_SYS_RAWIO privilege for an SDLA firmware upgrade, with unknown impact and local attack vectors. NOTE: further investigation suggests that this issue requires root privileges to exploit, since it is protected by CAP_NET_ADMIN; thus it might not be a vulnerability, although capabilities provide finer distinctions between privilege levels.
0