Show filters
352 Total Results
Displaying 191-200 of 352
Sort by:
Attacker Value
Unknown
CVE-2006-4663
Disclosure Date: September 09, 2006 (last updated November 08, 2023)
The source code tar archive of the Linux kernel 2.6.16, 2.6.17.11, and possibly other versions specifies weak permissions (0666 and 0777) for certain files and directories, which might allow local users to insert Trojan horse source code that would be used during the next kernel compilation. NOTE: another researcher disputes the vulnerability, stating that he finds "Not a single world-writable file or directory." CVE analysis as of 20060908 indicates that permissions will only be weak under certain unusual or insecure scenarios
0
Attacker Value
Unknown
CVE-2006-4538
Disclosure Date: September 05, 2006 (last updated October 04, 2023)
Linux kernel 2.6.17 and earlier, when running on IA64 or SPARC platforms, allows local users to cause a denial of service (crash) via a malformed ELF file that triggers memory maps that cross region boundaries.
0
Attacker Value
Unknown
CVE-2006-3745
Disclosure Date: August 23, 2006 (last updated October 04, 2023)
Unspecified vulnerability in the sctp_make_abort_user function in the SCTP implementation in Linux 2.6.x before 2.6.17.10 and 2.4.23 up to 2.4.33 allows local users to cause a denial of service (panic) and possibly gain root privileges via unknown attack vectors.
0
Attacker Value
Unknown
CVE-2006-4145
Disclosure Date: August 21, 2006 (last updated October 04, 2023)
The Universal Disk Format (UDF) filesystem driver in Linux kernel 2.6.17 and earlier allows local users to cause a denial of service (hang and crash) via certain operations involving truncated files, as demonstrated via the dd command.
0
Attacker Value
Unknown
CVE-2006-3634
Disclosure Date: August 04, 2006 (last updated October 04, 2023)
The (1) __futex_atomic_op and (2) futex_atomic_cmpxchg_inatomic functions in Linux kernel 2.6.17-rc4 to 2.6.18-rc2 perform the atomic futex operation in the kernel address space instead of the user address space, which allows local users to cause a denial of service (crash).
0
Attacker Value
Unknown
CVE-2006-3468
Disclosure Date: July 21, 2006 (last updated October 04, 2023)
Linux kernel 2.6.x, when using both NFS and EXT3, allows remote attackers to cause a denial of service (file system panic) via a crafted UDP packet with a V2 lookup procedure that specifies a bad file handle (inode number), which triggers an error and causes an exported directory to be remounted read-only.
0
Attacker Value
Unknown
CVE-2006-3626
Disclosure Date: July 18, 2006 (last updated October 04, 2023)
Race condition in Linux kernel 2.6.17.4 and earlier allows local users to gain root privileges by using prctl with PR_SET_DUMPABLE in a way that causes /proc/self/environ to become setuid root.
0
Attacker Value
Unknown
CVE-2006-2936
Disclosure Date: July 10, 2006 (last updated October 04, 2023)
The ftdi_sio driver (usb/serial/ftdi_sio.c) in Linux kernel 2.6.x up to 2.6.17, and possibly later versions, allows local users to cause a denial of service (memory consumption) by writing more data to the serial port than the hardware can handle, which causes the data to be queued.
0
Attacker Value
Unknown
CVE-2006-2451
Disclosure Date: July 07, 2006 (last updated October 04, 2023)
The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of service (disk consumption) and possibly gain privileges via the PR_SET_DUMPABLE argument of the prctl function and a program that causes a core dump file to be created in a directory for which the user does not have permissions.
0
Attacker Value
Unknown
CVE-2006-2934
Disclosure Date: June 30, 2006 (last updated October 04, 2023)
SCTP conntrack (ip_conntrack_proto_sctp.c) in netfilter for Linux kernel 2.6.17 before 2.6.17.3 and 2.6.16 before 2.6.16.23 allows remote attackers to cause a denial of service (crash) via a packet without any chunks, which causes a variable to contain an invalid value that is later used to dereference a pointer.
0