Show filters
53 Total Results
Displaying 31-40 of 53
Sort by:
Attacker Value
Unknown

CVE-2008-4210

Disclosure Date: September 29, 2008 (last updated October 04, 2023)
fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.
0
Attacker Value
Unknown

CVE-2008-4113

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
The sctp_getsockopt_hmac_ident function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, relies on an untrusted length value to limit copying of data from kernel memory, which allows local users to obtain sensitive information via a crafted SCTP_HMAC_IDENT IOCTL request involving the sctp_getsockopt function.
0
Attacker Value
Unknown

CVE-2007-4567

Disclosure Date: December 21, 2007 (last updated October 04, 2023)
The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, which allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted IPv6 packet.
0
Attacker Value
Unknown

CVE-2007-3740

Disclosure Date: September 14, 2007 (last updated October 04, 2023)
The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges.
0
Attacker Value
Unknown

CVE-2005-4635

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The nl_fib_input function in fib_frontend.c in the Linux kernel before 2.6.15 does not check for valid lengths of the header and payload, which allows remote attackers to cause a denial of service (invalid memory reference) via malformed fib_lookup netlink messages.
0
Attacker Value
Unknown

CVE-2005-2709

Disclosure Date: November 20, 2005 (last updated February 22, 2025)
The sysctl functionality (sysctl.c) in Linux kernel before 2.6.14.1 allows local users to cause a denial of service (kernel oops) and possibly execute code by opening an interface file in /proc/sys/net/ipv4/conf/, waiting until the interface is unregistered, then obtaining and modifying function pointers in memory that was used for the ctl_table.
0
Attacker Value
Unknown

CVE-2005-1263

Disclosure Date: May 11, 2005 (last updated February 22, 2025)
The elf_core_dump function in binfmt_elf.c for Linux kernel 2.x.x to 2.2.27-rc2, 2.4.x to 2.4.31-pre1, and 2.6.x to 2.6.12-rc4 allows local users to execute arbitrary code via an ELF binary that, in certain conditions involving the create_elf_tables function, causes a negative length argument to pass a signed integer comparison, leading to a buffer overflow.
0
Attacker Value
Unknown

CVE-2005-0815

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corrupt memory via a crafted filesystem.
0
Attacker Value
Unknown

CVE-2005-0749

Disclosure Date: April 01, 2005 (last updated February 22, 2025)
The load_elf_library in the Linux kernel before 2.6.11.6 allows local users to cause a denial of service (kernel crash) via a crafted ELF library or executable, which causes a free of an invalid pointer.
0
Attacker Value
Unknown

CVE-2005-0504

Disclosure Date: March 14, 2005 (last updated February 22, 2025)
Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.
0