CVE-2008-1669
- EPSS 0.13%
- Published 08.05.2008 00:20:00
- Last modified 09.04.2025 00:30:58
Linux kernel before 2.6.25.2 does not apply a certain protection mechanism for fcntl functionality, which allows local users to (1) execute code in parallel or (2) exploit a race condition to obtain "re-ordered access to the descriptor table."
CVE-2008-1294
- EPSS 0.04%
- Published 02.05.2008 16:05:00
- Last modified 09.04.2025 00:30:58
Linux kernel 2.6.17, and other versions before 2.6.22, does not check when a user attempts to set RLIMIT_CPU to 0 until after the change is made, which allows local users to bypass intended resource limits.
CVE-2008-1375
- EPSS 0.05%
- Published 02.05.2008 16:05:00
- Last modified 09.04.2025 00:30:58
Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via unspecified vectors.
CVE-2008-1675
- EPSS 0.07%
- Published 02.05.2008 16:05:00
- Last modified 09.04.2025 00:30:58
The bdx_ioctl_priv function in the tehuti driver (tehuti.c) in Linux kernel 2.6.x before 2.6.25.1 does not properly check certain information related to register size, which has unspecified impact and local attack vectors, probably related to reading...
CVE-2008-1514
- EPSS 0.12%
- Published 26.03.2008 00:44:00
- Last modified 09.04.2025 00:30:58
arch/s390/kernel/ptrace.c in Linux kernel 2.6.9, and other versions before 2.6.27-rc6, on s390 platforms allows local users to cause a denial of service (kernel panic) via the user-area-padding test from the ptrace testsuite in 31-bit mode, which tri...
CVE-2008-0009
- EPSS 1%
- Published 12.02.2008 21:00:00
- Last modified 09.04.2025 00:30:58
The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations.
CVE-2008-0010
- EPSS 0.24%
- Published 12.02.2008 21:00:00
- Last modified 09.04.2025 00:30:58
The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which allow local users to read from arbitrary kernel memory locations.
CVE-2008-0163
- EPSS 0.03%
- Published 12.02.2008 21:00:00
- Last modified 09.04.2025 00:30:58
Linux kernel 2.6, when using vservers, allows local users to access resources of other vservers via a symlink attack in /proc.
CVE-2008-0600
- EPSS 0.45%
- Published 12.02.2008 21:00:00
- Last modified 09.04.2025 00:30:58
The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows local users to gain root privileges via crafted arguments in a vmsplice system call, a different vuln...
CVE-2008-0007
- EPSS 0.11%
- Published 08.02.2008 02:00:00
- Last modified 09.04.2025 00:30:58
Linux kernel before 2.6.22.17, when using certain drivers that register a fault handler that does not perform range checks, allows local users to access kernel memory via an out-of-range offset.