Show filters
160 Total Results
Displaying 81-90 of 160
Sort by:
Attacker Value
Unknown

CVE-2008-1673

Disclosure Date: June 10, 2008 (last updated October 04, 2023)
The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (b) the gxsnmp package; does not properly validate length values during decoding of ASN.1 BER data, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a length greater than the working buffer, which can lead to an unspecified overflow; (2) an oid length of zero, which can lead to an off-by-one error; or (3) an indefinite length for a primitive encoding.
0
Attacker Value
Unknown

CVE-2008-2137

Disclosure Date: May 29, 2008 (last updated October 04, 2023)
The (1) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c and the (2) sparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3, omit some virtual-address range (aka span) checks when the mmap MAP_FIXED bit is not set, which allows local users to cause a denial of service (panic) via unspecified mmap calls.
0
Attacker Value
Unknown

CVE-2008-1669

Disclosure Date: May 08, 2008 (last updated October 04, 2023)
Linux kernel before 2.6.25.2 does not apply a certain protection mechanism for fcntl functionality, which allows local users to (1) execute code in parallel or (2) exploit a race condition to obtain "re-ordered access to the descriptor table."
0
Attacker Value
Unknown

CVE-2008-1675

Disclosure Date: May 02, 2008 (last updated October 04, 2023)
The bdx_ioctl_priv function in the tehuti driver (tehuti.c) in Linux kernel 2.6.x before 2.6.25.1 does not properly check certain information related to register size, which has unspecified impact and local attack vectors, probably related to reading or writing kernel memory.
0
Attacker Value
Unknown

CVE-2008-1514

Disclosure Date: March 26, 2008 (last updated October 04, 2023)
arch/s390/kernel/ptrace.c in Linux kernel 2.6.9, and other versions before 2.6.27-rc6, on s390 platforms allows local users to cause a denial of service (kernel panic) via the user-area-padding test from the ptrace testsuite in 31-bit mode, which triggers an invalid dereference.
0
Attacker Value
Unknown

CVE-2007-6694

Disclosure Date: January 29, 2008 (last updated October 04, 2023)
The chrp_show_cpuinfo function (chrp/setup.c) in Linux kernel 2.4.21 through 2.6.18-53, when running on PowerPC, might allow local users to cause a denial of service (crash) via unknown vectors that cause the of_get_property function to fail, which triggers a NULL pointer dereference.
0
Attacker Value
Unknown

CVE-2008-0001

Disclosure Date: January 15, 2008 (last updated October 04, 2023)
VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories.
0
Attacker Value
Unknown

CVE-2007-5093

Disclosure Date: September 26, 2007 (last updated November 08, 2023)
The disconnect method in the Philips USB Webcam (pwc) driver in Linux kernel 2.6.x before 2.6.22.6 "relies on user space to close the device," which allows user-assisted local attackers to cause a denial of service (USB subsystem hang and CPU consumption in khubd) by not closing the device after the disconnect is invoked. NOTE: this rarely crosses privilege boundaries, unless the attacker can convince the victim to unplug the affected device.
0
Attacker Value
Unknown

CVE-2007-3107

Disclosure Date: July 10, 2007 (last updated October 04, 2023)
The signal handling in the Linux kernel before 2.6.22, including 2.6.2, when running on PowerPC systems using HTX, allows local users to cause a denial of service via unspecified vectors involving floating point corruption and concurrency, related to clearing of MSR bits.
0
Attacker Value
Unknown

CVE-2007-3642

Disclosure Date: July 10, 2007 (last updated October 04, 2023)
The decode_choice function in net/netfilter/nf_conntrack_h323_asn1.c in the Linux kernel before 2.6.20.15, 2.6.21.x before 2.6.21.6, and before 2.6.22 allows remote attackers to cause a denial of service (crash) via an encoded, out-of-range index value for a choice field, which triggers a NULL pointer dereference.
0