Show filters
53 Total Results
Displaying 41-50 of 53
Sort by:
Attacker Value
Unknown

CVE-2004-1137

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers to cause a denial of service or execute arbitrary code via (1) the ip_mc_source function, which decrements a counter to -1, or (2) the igmp_marksources function, which does not properly validate IGMP message parameters and performs an out-of-bounds read.
0
Attacker Value
Unknown

CVE-2004-1070

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code.
0
Attacker Value
Unknown

CVE-2004-1073

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, allows local users to read non-readable ELF binaries by using the interpreter (PT_INTERP) functionality.
0
Attacker Value
Unknown

CVE-2004-1016

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of service (system hang) via crafted auxiliary messages that are passed to the sendmsg function, which causes a deadlock condition.
0
Attacker Value
Unknown

CVE-2004-2607

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
A numeric casting discrepancy in sdla_xfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users to read portions of kernel memory via a large len argument, which is received as an int but cast to a short, which prevents a read loop from filling a buffer.
0
Attacker Value
Unknown

CVE-2004-2731

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Multiple integer overflows in Sbus PROM driver (drivers/sbus/char/openprom.c) for the Linux kernel 2.4.x up to 2.4.27, 2.6.x up to 2.6.7, and possibly later versions, allow local users to execute arbitrary code by specifying (1) a small buffer size to the copyin_string function or (2) a negative buffer size to the copyin function.
0
Attacker Value
Unknown

CVE-2004-0814

Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote attackers to cause a denial of service (panic) by switching from console to PPP line discipline, then quickly sending data that is received during the switch.
0
Attacker Value
Unknown

CVE-2004-0685

Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous usage.
0
Attacker Value
Unknown

CVE-2004-1335

Disclosure Date: December 15, 2004 (last updated February 22, 2025)
Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory consumption) by repeatedly calling the ip_cmsg_send function.
0
Attacker Value
Unknown

CVE-2004-1333

Disclosure Date: December 15, 2004 (last updated February 22, 2025)
Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a buffer overflow.
0