CVE-2007-1734
- EPSS 0.21%
- Veröffentlicht 28.03.2007 22:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify the upper bounds of the optlen value, which allows local users running on certain architectures to read kernel memory or cause a ...
CVE-2007-1730
- EPSS 0.38%
- Veröffentlicht 28.03.2007 10:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later allows local users to read kernel memory or cause a denial of service (oops) via a negative optlen value.
CVE-2007-1592
- EPSS 0.24%
- Veröffentlicht 22.03.2007 19:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
net/ipv6/tcp_ipv6.c in Linux kernel 2.6.x up to 2.6.21-rc3 inadvertently copies the ipv6_fl_socklist from a listening TCP socket to child sockets, which allows local users to cause a denial of service (OOPS) or double free by opening a listening IPv6...
CVE-2007-1496
- EPSS 0.05%
- Veröffentlicht 16.03.2007 22:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
nfnetlink_log in netfilter in the Linux kernel before 2.6.20.3 allows attackers to cause a denial of service (crash) via unspecified vectors involving the (1) nfulnl_recv_config function, (2) using "multiple packets per netlink message", and (3) brid...
- EPSS 1.94%
- Veröffentlicht 16.03.2007 22:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
nf_conntrack in netfilter in the Linux kernel before 2.6.20.3 does not set nfctinfo during reassembly of fragmented packets, which leaves the default value as IP_CT_ESTABLISHED and might allow remote attackers to bypass certain rulesets using IPv6 fr...
CVE-2007-1000
- EPSS 0.27%
- Veröffentlicht 12.03.2007 23:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglue.c in the Linux kernel before 2.6.20.2 allows local users to read arbitrary kernel memory via certain getsockopt calls that trigger a NULL dereference.
CVE-2007-1388
- EPSS 0.14%
- Veröffentlicht 10.03.2007 19:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The do_ipv6_setsockopt function in net/ipv6/ipv6_sockglue.c in Linux kernel before 2.6.20, and possibly other versions, allows local users to cause a denial of service (oops) by calling setsockopt with the IPV6_RTHDR option name and possibly a zero o...
CVE-2007-1217
- EPSS 0.06%
- Veröffentlicht 02.03.2007 21:18:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the bufprint function in capiutil.c in libcapi, as used in Linux kernel 2.6.9 to 2.6.20 and isdn4k-utils, allows local users to cause a denial of service (crash) and possibly gain privileges via a crafted CAPI packet.
CVE-2006-7051
- EPSS 0.12%
- Veröffentlicht 24.02.2007 00:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (memory consumption) and possibly bypass memory limits or cause other processes to be killed by creating a large number of posix ti...
CVE-2007-0772
- EPSS 2.67%
- Veröffentlicht 20.02.2007 17:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Linux kernel 2.6.13 and other versions before 2.6.20.1 allows remote attackers to cause a denial of service (oops) via a crafted NFSACL 2 ACCESS request that triggers a free of an incorrect pointer.