CVE-2008-2750
- EPSS 9.72%
- Veröffentlicht 18.06.2008 19:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The pppol2tp_recvmsg function in drivers/net/pppol2tp.c in the Linux kernel 2.6 before 2.6.26-rc6 allows remote attackers to cause a denial of service (kernel heap memory corruption and system crash) and possibly have unspecified other impact via a c...
- EPSS 18.36%
- Veröffentlicht 10.06.2008 00:32:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (b) the gxsnmp package; does not properly validate length values during decoding of ASN.1 BER data, wh...
CVE-2008-2358
- EPSS 0.07%
- Veröffentlicht 10.06.2008 00:32:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.6.20, allows local users to gain privileges via an invalid feature leng...
CVE-2008-2137
- EPSS 0.09%
- Veröffentlicht 29.05.2008 16:32:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The (1) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c and the (2) sparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3, omit some virtual-address range (aka span)...
CVE-2008-2136
- EPSS 23.49%
- Veröffentlicht 16.05.2008 12:54:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to cause a denial of service (memory consumption) via network traffic to a Simple Internet Transition (SIT...
CVE-2008-2148
- EPSS 0.07%
- Veröffentlicht 12.05.2008 21:20:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The utimensat system call (sys_utimensat) in Linux kernel 2.6.22 and other versions before 2.6.25.3 does not check file permissions when certain UTIME_NOW and UTIME_OMIT combinations are used, which allows local users to modify file times of arbitrar...
CVE-2007-5498
- EPSS 0.05%
- Veröffentlicht 08.05.2008 00:20:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Xen hypervisor block backend driver for Linux kernel 2.6.18, when running on a 64-bit host with a 32-bit paravirtualized guest, allows local privileged users in the guest OS to cause a denial of service (host OS crash) via a request that specifie...
CVE-2008-1669
- EPSS 0.12%
- Veröffentlicht 08.05.2008 00:20:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Linux kernel before 2.6.25.2 does not apply a certain protection mechanism for fcntl functionality, which allows local users to (1) execute code in parallel or (2) exploit a race condition to obtain "re-ordered access to the descriptor table."
CVE-2008-1294
- EPSS 0.04%
- Veröffentlicht 02.05.2008 16:05:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Linux kernel 2.6.17, and other versions before 2.6.22, does not check when a user attempts to set RLIMIT_CPU to 0 until after the change is made, which allows local users to bypass intended resource limits.
CVE-2008-1375
- EPSS 0.07%
- Veröffentlicht 02.05.2008 16:05:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via unspecified vectors.