CVE-2008-3915
- EPSS 5.8%
- Published 11.09.2008 01:13:41
- Last modified 09.04.2025 00:30:58
Buffer overflow in nfsd in the Linux kernel before 2.6.26.4, when NFSv4 is enabled, allows remote attackers to have an unknown impact via vectors related to decoding an NFSv4 acl.
CVE-2007-6716
- EPSS 0.04%
- Published 04.09.2008 17:41:00
- Last modified 09.04.2025 00:30:58
fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.
CVE-2008-3911
- EPSS 0.05%
- Published 04.09.2008 17:41:00
- Last modified 09.04.2025 00:30:58
The proc_do_xprt function in net/sunrpc/sysctl.c in the Linux kernel 2.6.26.3 does not check the length of a certain buffer obtained from userspace, which allows local users to overflow a stack-based buffer and have unspecified other impact via a cra...
CVE-2008-3525
- EPSS 0.06%
- Published 03.09.2008 14:12:00
- Last modified 09.04.2025 00:30:58
The sbni_ioctl function in drivers/net/wan/sbni.c in the wan subsystem in the Linux kernel 2.6.26.3 does not check for the CAP_NET_ADMIN capability before processing a (1) SIOCDEVRESINSTATS, (2) SIOCDEVSHWSTATE, (3) SIOCDEVENSLAVE, or (4) SIOCDEVEMAN...
CVE-2008-3792
- EPSS 4.44%
- Published 03.09.2008 14:12:00
- Last modified 09.04.2025 00:30:58
net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4 does not verify that the SCTP-AUTH extension is enabled before proceeding with SCTP-AUTH API functions, which allows attackers to ...
CVE-2008-3526
- EPSS 1.91%
- Published 27.08.2008 20:41:00
- Last modified 09.04.2025 00:30:58
Integer overflow in the sctp_setsockopt_auth_key function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel 2.6.24-rc1 through 2.6.26.3 allows remote attackers to cause a denial of service (pan...
CVE-2008-3276
- EPSS 4.45%
- Published 18.08.2008 17:41:00
- Last modified 09.04.2025 00:30:58
Integer overflow in the dccp_setsockopt_change function in net/dccp/proto.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.17-rc1 through 2.6.26.2 allows remote attackers to cause a denial of service (panic) via ...
CVE-2008-3686
- EPSS 0.07%
- Published 14.08.2008 22:41:00
- Last modified 09.04.2025 00:30:58
The rt6_fill_node function in net/ipv6/route.c in Linux kernel 2.6.26-rc4, 2.6.26.2, and possibly other 2.6.26 versions, allows local users to cause a denial of service (kernel OOPS) via IPv6 requests when no IPv6 input device is in use, which trigge...
CVE-2008-3275
- EPSS 0.08%
- Published 12.08.2008 23:41:00
- Last modified 09.04.2025 00:30:58
The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denia...
CVE-2008-3534
- EPSS 0.05%
- Published 08.08.2008 19:41:00
- Last modified 09.04.2025 00:30:58
The shmem_delete_inode function in mm/shmem.c in the tmpfs implementation in the Linux kernel before 2.6.26.1 allows local users to cause a denial of service (system crash) via a certain sequence of file create, remove, and overwrite operations, as d...