Show filters
85 Total Results
Displaying 51-60 of 85
Sort by:
Attacker Value
Unknown

CVE-2009-1360

Disclosure Date: April 22, 2009 (last updated October 04, 2023)
The __inet6_check_established function in net/ipv6/inet6_hashtables.c in the Linux kernel before 2.6.29, when Network Namespace Support (aka NET_NS) is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via vectors involving IPv6 packets.
0
Attacker Value
Unknown

CVE-2009-1337

Disclosure Date: April 22, 2009 (last updated October 04, 2023)
The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application.
0
Attacker Value
Unknown

CVE-2009-1338

Disclosure Date: April 22, 2009 (last updated October 04, 2023)
The kill_something_info function in kernel/signal.c in the Linux kernel before 2.6.28 does not consider PID namespaces when processing signals directed to PID -1, which allows local users to bypass the intended namespace isolation, and send arbitrary signals to all processes in all namespaces, via a kill command.
0
Attacker Value
Unknown

CVE-2009-0028

Disclosure Date: February 27, 2009 (last updated October 04, 2023)
The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting this new process exit.
0
Attacker Value
Unknown

CVE-2009-0675

Disclosure Date: February 22, 2009 (last updated October 04, 2023)
The skfp_ioctl function in drivers/net/skfp/skfddi.c in the Linux kernel before 2.6.28.6 permits SKFP_CLR_STATS requests only when the CAP_NET_ADMIN capability is absent, instead of when this capability is present, which allows local users to reset the driver statistics, related to an "inverted logic" issue.
0
Attacker Value
Unknown

CVE-2009-0676

Disclosure Date: February 22, 2009 (last updated October 04, 2023)
The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt request.
0
Attacker Value
Unknown

CVE-2009-0605

Disclosure Date: February 17, 2009 (last updated October 04, 2023)
Stack consumption vulnerability in the do_page_fault function in arch/x86/mm/fault.c in the Linux kernel before 2.6.28.5 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via unspecified vectors that trigger page faults on a machine that has a registered Kprobes probe.
0
Attacker Value
Unknown

CVE-2008-6107

Disclosure Date: February 10, 2009 (last updated October 04, 2023)
The (1) sys32_mremap function in arch/sparc64/kernel/sys_sparc32.c, the (2) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c, and the (3) sparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the Linux kernel before 2.6.25.4, omit some virtual-address range (aka span) checks when the mremap MREMAP_FIXED bit is not set, which allows local users to cause a denial of service (panic) via unspecified mremap calls, a related issue to CVE-2008-2137.
0
Attacker Value
Unknown

CVE-2009-0031

Disclosure Date: January 21, 2009 (last updated October 04, 2023)
Memory leak in the keyctl_join_session_keyring function (security/keys/keyctl.c) in Linux kernel 2.6.29-rc2 and earlier allows local users to cause a denial of service (kernel memory consumption) via unknown vectors related to a "missing kfree."
0
Attacker Value
Unknown

CVE-2008-4307

Disclosure Date: January 13, 2009 (last updated October 04, 2023)
Race condition in the do_setlk function in fs/nfs/file.c in the Linux kernel before 2.6.26 allows local users to cause a denial of service (crash) via vectors resulting in an interrupted RPC call that leads to a stray FL_POSIX lock, related to improper handling of a race between fcntl and close in the EINTR case.
0