Show filters
150 Total Results
Displaying 141-150 of 150
Sort by:
Attacker Value
Unknown

CVE-2005-3806

Disclosure Date: November 25, 2005 (last updated February 22, 2025)
The IPv6 flow label handling code (ip6_flowlabel.c) in Linux kernels 2.4 up to 2.4.32 and 2.6 before 2.6.14 modifies the wrong variable in certain circumstances, which allows local users to corrupt kernel memory or cause a denial of service (crash) by triggering a free of non-allocated memory.
0
Attacker Value
Unknown

CVE-2005-3784

Disclosure Date: November 23, 2005 (last updated February 22, 2025)
The auto-reap of child processes in Linux kernel 2.6 before 2.6.15 includes processes with ptrace attached, which leads to a dangling ptrace reference and allows local users to cause a denial of service (crash) and gain root privileges.
0
Attacker Value
Unknown

CVE-2005-3783

Disclosure Date: November 23, 2005 (last updated February 22, 2025)
The ptrace functionality (ptrace.c) in Linux kernel 2.6 before 2.6.14.2, using CLONE_THREAD, does not use the thread group ID to check whether it is attaching to itself, which allows local users to cause a denial of service (crash).
0
Attacker Value
Unknown

CVE-2005-2709

Disclosure Date: November 20, 2005 (last updated February 22, 2025)
The sysctl functionality (sysctl.c) in Linux kernel before 2.6.14.1 allows local users to cause a denial of service (kernel oops) and possibly execute code by opening an interface file in /proc/sys/net/ipv4/conf/, waiting until the interface is unregistered, then obtaining and modifying function pointers in memory that was used for the ctl_table.
0
Attacker Value
Unknown

CVE-2005-2973

Disclosure Date: October 27, 2005 (last updated February 22, 2025)
The udp_v6_get_port function in udp.c in Linux 2.6 before 2.6.14-rc5, when running IPv6, allows local users to cause a denial of service (infinite loop and crash).
0
Attacker Value
Unknown

CVE-2005-3272

Disclosure Date: October 21, 2005 (last updated February 22, 2025)
Linux kernel before 2.6.12 allows remote attackers to poison the bridge forwarding table using frames that have already been dropped by filtering, which can cause the bridge to forward spoofed packets.
0
Attacker Value
Unknown

CVE-2005-3276

Disclosure Date: October 21, 2005 (last updated February 22, 2025)
The sys_get_thread_area function in process.c in Linux 2.6 before 2.6.12.4 and 2.6.13 does not clear a data structure before copying it to userspace, which might allow a user process to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2005-3273

Disclosure Date: October 21, 2005 (last updated February 22, 2025)
The rose_rt_ioctl function in rose_route.c for Radionet Open Source Environment (ROSE) in Linux 2.6 kernels before 2.6.12, and 2.4 before 2.4.29, does not properly verify the ndigis argument for a new route, which allows attackers to trigger array out-of-bounds errors with a large number of digipeats.
0
Attacker Value
Unknown

CVE-2005-3275

Disclosure Date: October 21, 2005 (last updated February 22, 2025)
The NAT code (1) ip_nat_proto_tcp.c and (2) ip_nat_proto_udp.c in Linux kernel 2.6 before 2.6.13 and 2.4 before 2.4.32-rc1 incorrectly declares a variable to be static, which allows remote attackers to cause a denial of service (memory corruption) by causing two packets for the same protocol to be NATed at the same time, which leads to memory corruption.
0
Attacker Value
Unknown

CVE-2005-3179

Disclosure Date: October 12, 2005 (last updated February 22, 2025)
drm.c in Linux kernel 2.6.10 to 2.6.13 creates a debug file in sysfs with world-readable and world-writable permissions, which allows local users to enable DRM debugging and obtain sensitive information.
0