Show filters
53 Total Results
Displaying 31-40 of 53
Sort by:
Attacker Value
Unknown
CVE-2008-4210
Disclosure Date: September 29, 2008 (last updated October 04, 2023)
fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.
0
Attacker Value
Unknown
CVE-2008-4113
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
The sctp_getsockopt_hmac_ident function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, relies on an untrusted length value to limit copying of data from kernel memory, which allows local users to obtain sensitive information via a crafted SCTP_HMAC_IDENT IOCTL request involving the sctp_getsockopt function.
0
Attacker Value
Unknown
CVE-2007-4567
Disclosure Date: December 21, 2007 (last updated October 04, 2023)
The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, which allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted IPv6 packet.
0
Attacker Value
Unknown
CVE-2007-3740
Disclosure Date: September 14, 2007 (last updated October 04, 2023)
The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges.
0
Attacker Value
Unknown
CVE-2005-4635
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The nl_fib_input function in fib_frontend.c in the Linux kernel before 2.6.15 does not check for valid lengths of the header and payload, which allows remote attackers to cause a denial of service (invalid memory reference) via malformed fib_lookup netlink messages.
0
Attacker Value
Unknown
CVE-2005-2709
Disclosure Date: November 20, 2005 (last updated February 22, 2025)
The sysctl functionality (sysctl.c) in Linux kernel before 2.6.14.1 allows local users to cause a denial of service (kernel oops) and possibly execute code by opening an interface file in /proc/sys/net/ipv4/conf/, waiting until the interface is unregistered, then obtaining and modifying function pointers in memory that was used for the ctl_table.
0
Attacker Value
Unknown
CVE-2005-1263
Disclosure Date: May 11, 2005 (last updated February 22, 2025)
The elf_core_dump function in binfmt_elf.c for Linux kernel 2.x.x to 2.2.27-rc2, 2.4.x to 2.4.31-pre1, and 2.6.x to 2.6.12-rc4 allows local users to execute arbitrary code via an ELF binary that, in certain conditions involving the create_elf_tables function, causes a negative length argument to pass a signed integer comparison, leading to a buffer overflow.
0
Attacker Value
Unknown
CVE-2005-0815
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corrupt memory via a crafted filesystem.
0
Attacker Value
Unknown
CVE-2005-0749
Disclosure Date: April 01, 2005 (last updated February 22, 2025)
The load_elf_library in the Linux kernel before 2.6.11.6 allows local users to cause a denial of service (kernel crash) via a crafted ELF library or executable, which causes a free of an invalid pointer.
0
Attacker Value
Unknown
CVE-2005-0504
Disclosure Date: March 14, 2005 (last updated February 22, 2025)
Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.
0