Show filters
53 Total Results
Displaying 41-50 of 53
Sort by:
Attacker Value
Unknown
CVE-2004-1137
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers to cause a denial of service or execute arbitrary code via (1) the ip_mc_source function, which decrements a counter to -1, or (2) the igmp_marksources function, which does not properly validate IGMP message parameters and performs an out-of-bounds read.
0
Attacker Value
Unknown
CVE-2004-1070
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code.
0
Attacker Value
Unknown
CVE-2004-1073
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, allows local users to read non-readable ELF binaries by using the interpreter (PT_INTERP) functionality.
0
Attacker Value
Unknown
CVE-2004-1016
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of service (system hang) via crafted auxiliary messages that are passed to the sendmsg function, which causes a deadlock condition.
0
Attacker Value
Unknown
CVE-2004-2607
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
A numeric casting discrepancy in sdla_xfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users to read portions of kernel memory via a large len argument, which is received as an int but cast to a short, which prevents a read loop from filling a buffer.
0
Attacker Value
Unknown
CVE-2004-2731
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Multiple integer overflows in Sbus PROM driver (drivers/sbus/char/openprom.c) for the Linux kernel 2.4.x up to 2.4.27, 2.6.x up to 2.6.7, and possibly later versions, allow local users to execute arbitrary code by specifying (1) a small buffer size to the copyin_string function or (2) a negative buffer size to the copyin function.
0
Attacker Value
Unknown
CVE-2004-0814
Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote attackers to cause a denial of service (panic) by switching from console to PPP line discipline, then quickly sending data that is received during the switch.
0
Attacker Value
Unknown
CVE-2004-0685
Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous usage.
0
Attacker Value
Unknown
CVE-2004-1335
Disclosure Date: December 15, 2004 (last updated February 22, 2025)
Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory consumption) by repeatedly calling the ip_cmsg_send function.
0
Attacker Value
Unknown
CVE-2004-1333
Disclosure Date: December 15, 2004 (last updated February 22, 2025)
Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a buffer overflow.
0