Show filters
111 Total Results
Displaying 91-100 of 111
Sort by:
Attacker Value
Unknown

CVE-2008-2137

Disclosure Date: May 29, 2008 (last updated October 04, 2023)
The (1) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c and the (2) sparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3, omit some virtual-address range (aka span) checks when the mmap MAP_FIXED bit is not set, which allows local users to cause a denial of service (panic) via unspecified mmap calls.
0
Attacker Value
Unknown

CVE-2008-1669

Disclosure Date: May 08, 2008 (last updated October 04, 2023)
Linux kernel before 2.6.25.2 does not apply a certain protection mechanism for fcntl functionality, which allows local users to (1) execute code in parallel or (2) exploit a race condition to obtain "re-ordered access to the descriptor table."
0
Attacker Value
Unknown

CVE-2008-1294

Disclosure Date: May 02, 2008 (last updated October 04, 2023)
Linux kernel 2.6.17, and other versions before 2.6.22, does not check when a user attempts to set RLIMIT_CPU to 0 until after the change is made, which allows local users to bypass intended resource limits.
0
Attacker Value
Unknown

CVE-2008-1675

Disclosure Date: May 02, 2008 (last updated October 04, 2023)
The bdx_ioctl_priv function in the tehuti driver (tehuti.c) in Linux kernel 2.6.x before 2.6.25.1 does not properly check certain information related to register size, which has unspecified impact and local attack vectors, probably related to reading or writing kernel memory.
0
Attacker Value
Unknown

CVE-2008-1514

Disclosure Date: March 26, 2008 (last updated October 04, 2023)
arch/s390/kernel/ptrace.c in Linux kernel 2.6.9, and other versions before 2.6.27-rc6, on s390 platforms allows local users to cause a denial of service (kernel panic) via the user-area-padding test from the ptrace testsuite in 31-bit mode, which triggers an invalid dereference.
0
Attacker Value
Unknown

CVE-2008-0600

Disclosure Date: February 12, 2008 (last updated October 04, 2023)
The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows local users to gain root privileges via crafted arguments in a vmsplice system call, a different vulnerability than CVE-2008-0009 and CVE-2008-0010.
0
Attacker Value
Unknown

CVE-2008-0352

Disclosure Date: January 18, 2008 (last updated October 04, 2023)
The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6 packet, possibly involving the Jumbo Payload hop-by-hop option (jumbogram).
0
Attacker Value
Unknown

CVE-2008-0001

Disclosure Date: January 15, 2008 (last updated October 04, 2023)
VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories.
0
Attacker Value
Unknown

CVE-2007-4567

Disclosure Date: December 21, 2007 (last updated October 04, 2023)
The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, which allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted IPv6 packet.
0
Attacker Value
Unknown

CVE-2007-5093

Disclosure Date: September 26, 2007 (last updated November 08, 2023)
The disconnect method in the Philips USB Webcam (pwc) driver in Linux kernel 2.6.x before 2.6.22.6 "relies on user space to close the device," which allows user-assisted local attackers to cause a denial of service (USB subsystem hang and CPU consumption in khubd) by not closing the device after the disconnect is invoked. NOTE: this rarely crosses privilege boundaries, unless the attacker can convince the victim to unplug the affected device.
0