CVE-2007-4573
- EPSS 0.16%
- Veröffentlicht 24.09.2007 22:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users t...
CVE-2007-0997
- EPSS 0.04%
- Veröffentlicht 18.09.2007 19:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Race condition in the tee (sys_tee) system call in the Linux kernel 2.6.17 through 2.6.17.6 might allow local users to cause a denial of service (system crash), obtain sensitive information (kernel memory contents), or gain privileges via unspecified...
CVE-2007-3731
- EPSS 0.04%
- Veröffentlicht 17.09.2007 17:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Linux kernel 2.6.20 and 2.6.21 does not properly handle an invalid LDT segment selector in %cs (the xcs field) during ptrace single-step operations, which allows local users to cause a denial of service (NULL dereference and OOPS) via certain cod...
CVE-2007-3740
- EPSS 0.07%
- Veröffentlicht 14.09.2007 01:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges.
CVE-2007-3848
- EPSS 0.11%
- Veröffentlicht 14.08.2007 17:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Linux kernel 2.4.35 and other versions allows local users to send arbitrary signals to a child process that is running at higher privileges by causing a setuid-root parent process to die, which delivers an attacker-controlled parent process death sig...
CVE-2007-4311
- EPSS 0.61%
- Veröffentlicht 13.08.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The xfer_secondary_pool function in drivers/char/random.c in the Linux kernel 2.4 before 2.4.35 performs reseed operations on only the first few bytes of a buffer, which might make it easier for attackers to predict the output of the random number ge...
- EPSS 0.06%
- Veröffentlicht 13.08.2007 19:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The drm/i915 component in the Linux kernel before 2.6.22.2, when used with i965G and later chipsets, allows local users with access to an X11 session and Direct Rendering Manager (DRM) to write to arbitrary memory locations and gain privileges via a ...
CVE-2007-3843
- EPSS 2.04%
- Veröffentlicht 09.08.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Linux kernel before 2.6.23-rc1 checks the wrong global variable for the CIFS sec mount option, which might allow remote attackers to spoof CIFS network traffic that the client configured for security signatures, as demonstrated by lack of signing...
CVE-2007-3105
- EPSS 0.13%
- Veröffentlicht 27.07.2007 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in the random number generator (RNG) implementation in the Linux kernel before 2.6.22 might allow local root users to cause a denial of service or gain privileges by setting the default wakeup threshold to a value greater ...
- EPSS 3.2%
- Veröffentlicht 20.07.2007 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Distributed Lock Manager (DLM) in the cluster manager for Linux kernel 2.6.15 allows remote attackers to cause a denial of service (loss of lock services) by connecting to the DLM port, which probably prevents other processes from accessing the s...