Show filters
85 Total Results
Displaying 21-30 of 85
Sort by:
Attacker Value
Unknown
CVE-2010-1088
Disclosure Date: April 06, 2010 (last updated October 04, 2023)
fs/namei.c in Linux kernel 2.6.18 through 2.6.34 does not always follow NFS automount "symlinks," which allows attackers to have an unknown impact, related to LOOKUP_FOLLOW.
0
Attacker Value
Unknown
CVE-2010-1083
Disclosure Date: April 06, 2010 (last updated October 04, 2023)
The processcompl_compat function in drivers/usb/core/devio.c in Linux kernel 2.6.x through 2.6.32, and possibly other versions, does not clear the transfer buffer before returning to userspace when a USB command fails, which might make it easier for physically proximate attackers to obtain sensitive information (kernel memory).
0
Attacker Value
Unknown
CVE-2010-1084
Disclosure Date: April 06, 2010 (last updated October 04, 2023)
Linux kernel 2.6.18 through 2.6.33, and possibly other versions, allows remote attackers to cause a denial of service (memory corruption) via a large number of Bluetooth sockets, related to the size of sysfs files in (1) net/bluetooth/l2cap.c, (2) net/bluetooth/rfcomm/core.c, (3) net/bluetooth/rfcomm/sock.c, and (4) net/bluetooth/sco.c.
0
Attacker Value
Unknown
CVE-2010-0437
Disclosure Date: March 24, 2010 (last updated October 04, 2023)
The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving an IPv6 TUN network interface and a large number of neighbors, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via unknown vectors.
0
Attacker Value
Unknown
CVE-2010-0415
Disclosure Date: February 17, 2010 (last updated October 04, 2023)
The do_pages_move function in mm/migrate.c in the Linux kernel before 2.6.33-rc7 does not validate node values, which allows local users to read arbitrary kernel memory locations, cause a denial of service (OOPS), and possibly have unspecified other impact by specifying a node that is not part of the kernel's node set.
0
Attacker Value
Unknown
CVE-2010-0622
Disclosure Date: February 15, 2010 (last updated October 04, 2023)
The wake_futex_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly handle certain unlock operations for a Priority Inheritance (PI) futex, which allows local users to cause a denial of service (OOPS) and possibly have unspecified other impact via vectors involving modification of the futex value from user space.
0
Attacker Value
Unknown
CVE-2009-4141
Disclosure Date: January 19, 2010 (last updated October 04, 2023)
Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privileges via vectors that include enabling O_ASYNC (aka FASYNC or FIOASYNC) on a locked file, and then closing this file.
0
Attacker Value
Unknown
CVE-2010-0007
Disclosure Date: January 19, 2010 (last updated October 04, 2023)
net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.
0
Attacker Value
Unknown
CVE-2009-4138
Disclosure Date: December 16, 2009 (last updated October 04, 2023)
drivers/firewire/ohci.c in the Linux kernel before 2.6.32-git9, when packet-per-buffer mode is used, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unknown other impact via an unspecified ioctl associated with receiving an ISO packet that contains zero in the payload-length field.
0
Attacker Value
Unknown
CVE-2009-4131
Disclosure Date: December 13, 2009 (last updated October 04, 2023)
The EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementation in the ext4 filesystem in the Linux kernel before 2.6.32-git6 allows local users to overwrite arbitrary files via a crafted request, related to insufficient checks for file permissions.
0