CVE-2008-3525
- EPSS 0.06%
- Veröffentlicht 03.09.2008 14:12:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The sbni_ioctl function in drivers/net/wan/sbni.c in the wan subsystem in the Linux kernel 2.6.26.3 does not check for the CAP_NET_ADMIN capability before processing a (1) SIOCDEVRESINSTATS, (2) SIOCDEVSHWSTATE, (3) SIOCDEVENSLAVE, or (4) SIOCDEVEMAN...
CVE-2008-3792
- EPSS 3.9%
- Veröffentlicht 03.09.2008 14:12:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4 does not verify that the SCTP-AUTH extension is enabled before proceeding with SCTP-AUTH API functions, which allows attackers to ...
CVE-2008-3526
- EPSS 1.91%
- Veröffentlicht 27.08.2008 20:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the sctp_setsockopt_auth_key function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel 2.6.24-rc1 through 2.6.26.3 allows remote attackers to cause a denial of service (pan...
CVE-2008-3276
- EPSS 4.45%
- Veröffentlicht 18.08.2008 17:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the dccp_setsockopt_change function in net/dccp/proto.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.17-rc1 through 2.6.26.2 allows remote attackers to cause a denial of service (panic) via ...
CVE-2008-3686
- EPSS 0.07%
- Veröffentlicht 14.08.2008 22:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The rt6_fill_node function in net/ipv6/route.c in Linux kernel 2.6.26-rc4, 2.6.26.2, and possibly other 2.6.26 versions, allows local users to cause a denial of service (kernel OOPS) via IPv6 requests when no IPv6 input device is in use, which trigge...
CVE-2008-3275
- EPSS 0.08%
- Veröffentlicht 12.08.2008 23:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denia...
CVE-2008-3534
- EPSS 0.05%
- Veröffentlicht 08.08.2008 19:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The shmem_delete_inode function in mm/shmem.c in the tmpfs implementation in the Linux kernel before 2.6.26.1 allows local users to cause a denial of service (system crash) via a certain sequence of file create, remove, and overwrite operations, as d...
CVE-2008-3535
- EPSS 0.05%
- Veröffentlicht 08.08.2008 19:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Off-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-rc2 allows local users to cause a denial of service (system crash) via a certain sequence of file I/O operations with readv and writev, as demonstrate...
CVE-2008-3272
- EPSS 0.06%
- Veröffentlicht 08.08.2008 18:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain da...
- EPSS 1.17%
- Veröffentlicht 06.08.2008 18:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in format descriptor parsing in the uvc_parse_format function in drivers/media/video/uvc/uvc_driver.c in uvcvideo in the video4linux (V4L) implementation in the Linux kernel before 2.6.26.1 has unknown impact and attack vectors.