CVE-2008-2729
- EPSS 0.06%
- Published 30.06.2008 22:41:00
- Last modified 09.04.2025 00:30:58
arch/x86_64/lib/copy_user.S in the Linux kernel before 2.6.19 on some AMD64 systems does not erase destination memory locations after an exception during kernel memory copy, which allows local users to obtain sensitive information.
CVE-2008-2365
- EPSS 1.36%
- Published 30.06.2008 21:41:00
- Last modified 09.04.2025 00:30:58
Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE_ATTACH ptrace calls to another ...
CVE-2008-2944
- EPSS 0.06%
- Published 30.06.2008 21:41:00
- Last modified 09.04.2025 00:30:58
Double free vulnerability in the utrace support in the Linux kernel, probably 2.6.18, in Red Hat Enterprise Linux (RHEL) 5 and Fedora Core 6 (FC6) allows local users to cause a denial of service (oops), as demonstrated by a crash when running the GNU...
CVE-2008-2750
- EPSS 12.06%
- Published 18.06.2008 19:41:00
- Last modified 09.04.2025 00:30:58
The pppol2tp_recvmsg function in drivers/net/pppol2tp.c in the Linux kernel 2.6 before 2.6.26-rc6 allows remote attackers to cause a denial of service (kernel heap memory corruption and system crash) and possibly have unspecified other impact via a c...
- EPSS 18.36%
- Published 10.06.2008 00:32:00
- Last modified 09.04.2025 00:30:58
The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (b) the gxsnmp package; does not properly validate length values during decoding of ASN.1 BER data, wh...
CVE-2008-2358
- EPSS 0.07%
- Published 10.06.2008 00:32:00
- Last modified 09.04.2025 00:30:58
Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.6.20, allows local users to gain privileges via an invalid feature leng...
CVE-2008-2137
- EPSS 0.09%
- Published 29.05.2008 16:32:00
- Last modified 09.04.2025 00:30:58
The (1) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c and the (2) sparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3, omit some virtual-address range (aka span)...
CVE-2008-2136
- EPSS 14.97%
- Published 16.05.2008 12:54:00
- Last modified 09.04.2025 00:30:58
Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to cause a denial of service (memory consumption) via network traffic to a Simple Internet Transition (SIT...
CVE-2008-2148
- EPSS 0.07%
- Published 12.05.2008 21:20:00
- Last modified 09.04.2025 00:30:58
The utimensat system call (sys_utimensat) in Linux kernel 2.6.22 and other versions before 2.6.25.3 does not check file permissions when certain UTIME_NOW and UTIME_OMIT combinations are used, which allows local users to modify file times of arbitrar...
CVE-2007-5498
- EPSS 0.05%
- Published 08.05.2008 00:20:00
- Last modified 09.04.2025 00:30:58
The Xen hypervisor block backend driver for Linux kernel 2.6.18, when running on a 64-bit host with a 32-bit paravirtualized guest, allows local privileged users in the guest OS to cause a denial of service (host OS crash) via a request that specifie...