Show filters
152 Total Results
Displaying 141-150 of 152
Sort by:
Attacker Value
Unknown
CVE-2006-2071
Disclosure Date: April 27, 2006 (last updated October 04, 2023)
Linux kernel 2.4.x and 2.6.x up to 2.6.16 allows local users to bypass IPC permissions and modify a readonly attachment of shared memory by using mprotect to give write permission to the attachment. NOTE: some original raw sources combined this issue with CVE-2006-1524, but they are different bugs.
0
Attacker Value
Unknown
CVE-2006-1864
Disclosure Date: April 26, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in smbfs in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to CVE-2006-1863.
0
Attacker Value
Unknown
CVE-2006-1056
Disclosure Date: April 20, 2006 (last updated October 04, 2023)
The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one process to determine portions of the state of floating point instructions of other processes, which can be leveraged to obtain sensitive information such as cryptographic keys. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processors in a security-relevant fashion that was not addressed by the kernels.
0
Attacker Value
Unknown
CVE-2006-1524
Disclosure Date: April 19, 2006 (last updated October 04, 2023)
madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability. NOTE: this description was originally written in a way that combined two separate issues. The mprotect issue now has a separate name, CVE-2006-2071.
0
Attacker Value
Unknown
CVE-2006-1525
Disclosure Date: April 19, 2006 (last updated October 04, 2023)
ip_route_input in Linux kernel 2.6 before 2.6.16.8 allows local users to cause a denial of service (panic) via a request for a route for a multicast IP address, which triggers a null dereference.
0
Attacker Value
Unknown
CVE-2006-0744
Disclosure Date: April 18, 2006 (last updated October 04, 2023)
Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the wrong GS.
0
Attacker Value
Unknown
CVE-2006-0558
Disclosure Date: April 14, 2006 (last updated October 04, 2023)
perfmon (perfmon.c) in Linux kernel on IA64 architectures allows local users to cause a denial of service (crash) by interrupting a task while another process is accessing the mm_struct, which triggers a BUG_ON action in the put_page_testzero function.
0
Attacker Value
Unknown
CVE-2006-1523
Disclosure Date: April 12, 2006 (last updated October 04, 2023)
The __group_complete_signal function in the RCU signal handling (signal.c) in Linux kernel 2.6.16, and possibly other versions, has unknown impact and attack vectors related to improper use of BUG_ON.
0
Attacker Value
Unknown
CVE-2006-1522
Disclosure Date: April 10, 2006 (last updated February 22, 2025)
The sys_add_key function in the keyring code in Linux kernel 2.6.16.1 and 2.6.17-rc1, and possibly earlier versions, allows local users to cause a denial of service (OOPS) via keyctl requests that add a key to a user key instead of a keyring key, which causes an invalid dereference in the __keyring_search_one function.
0
Attacker Value
Unknown
CVE-2006-1055
Disclosure Date: April 05, 2006 (last updated February 22, 2025)
The fill_write_buffer function in sysfs/file.c in Linux kernel 2.6.12 up to versions before 2.6.17-rc1 does not zero terminate a buffer when a length of PAGE_SIZE or more is requested, which might allow local users to cause a denial of service (crash) by causing an out-of-bounds read.
0