CVE-2008-4445
- EPSS 0.07%
- Veröffentlicht 06.10.2008 19:54:36
- Zuletzt bearbeitet 09.04.2025 00:30:58
The sctp_auth_ep_set_hmacs function in net/sctp/auth.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, does not verify that the identifier index is within...
CVE-2008-3833
- EPSS 0.04%
- Veröffentlicht 03.10.2008 17:41:40
- Zuletzt bearbeitet 09.04.2025 00:30:58
The generic_file_splice_write function in fs/splice.c in the Linux kernel before 2.6.19 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain s...
CVE-2008-4410
- EPSS 0.06%
- Veröffentlicht 03.10.2008 17:41:40
- Zuletzt bearbeitet 09.04.2025 00:30:58
The vmi_write_ldt_entry function in arch/x86/kernel/vmi_32.c in the Virtual Machine Interface (VMI) in the Linux kernel 2.6.26.5 invokes write_idt_entry where write_ldt_entry was intended, which allows local users to cause a denial of service (persis...
CVE-2008-4210
- EPSS 11.3%
- Veröffentlicht 29.09.2008 17:17:29
- Zuletzt bearbeitet 09.04.2025 00:30:58
fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspec...
CVE-2008-4302
- EPSS 0.16%
- Veröffentlicht 29.09.2008 17:17:29
- Zuletzt bearbeitet 09.04.2025 00:30:58
fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a deni...
CVE-2008-3528
- EPSS 0.35%
- Veröffentlicht 27.09.2008 10:30:03
- Zuletzt bearbeitet 09.04.2025 00:30:58
The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically prox...
CVE-2008-4113
- EPSS 0.19%
- Veröffentlicht 16.09.2008 23:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The sctp_getsockopt_hmac_ident function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, relies on an untrusted length value to limit ...
CVE-2008-3915
- EPSS 4.45%
- Veröffentlicht 11.09.2008 01:13:41
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in nfsd in the Linux kernel before 2.6.26.4, when NFSv4 is enabled, allows remote attackers to have an unknown impact via vectors related to decoding an NFSv4 acl.
CVE-2007-6716
- EPSS 0.05%
- Veröffentlicht 04.09.2008 17:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.
CVE-2008-3911
- EPSS 0.05%
- Veröffentlicht 04.09.2008 17:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The proc_do_xprt function in net/sunrpc/sysctl.c in the Linux kernel 2.6.26.3 does not check the length of a certain buffer obtained from userspace, which allows local users to overflow a stack-based buffer and have unspecified other impact via a cra...