CVE-2008-1675
- EPSS 0.07%
- Veröffentlicht 02.05.2008 16:05:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The bdx_ioctl_priv function in the tehuti driver (tehuti.c) in Linux kernel 2.6.x before 2.6.25.1 does not properly check certain information related to register size, which has unspecified impact and local attack vectors, probably related to reading...
CVE-2008-1514
- EPSS 0.09%
- Veröffentlicht 26.03.2008 00:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
arch/s390/kernel/ptrace.c in Linux kernel 2.6.9, and other versions before 2.6.27-rc6, on s390 platforms allows local users to cause a denial of service (kernel panic) via the user-area-padding test from the ptrace testsuite in 31-bit mode, which tri...
CVE-2008-0009
- EPSS 0.94%
- Veröffentlicht 12.02.2008 21:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations.
CVE-2008-0010
- EPSS 0.23%
- Veröffentlicht 12.02.2008 21:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which allow local users to read from arbitrary kernel memory locations.
CVE-2008-0163
- EPSS 0.03%
- Veröffentlicht 12.02.2008 21:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Linux kernel 2.6, when using vservers, allows local users to access resources of other vservers via a symlink attack in /proc.
CVE-2008-0600
- EPSS 0.31%
- Veröffentlicht 12.02.2008 21:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows local users to gain root privileges via crafted arguments in a vmsplice system call, a different vuln...
CVE-2008-0007
- EPSS 0.11%
- Veröffentlicht 08.02.2008 02:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Linux kernel before 2.6.22.17, when using certain drivers that register a fault handler that does not perform range checks, allows local users to access kernel memory via an out-of-range offset.
CVE-2007-4998
- EPSS 0.11%
- Veröffentlicht 31.01.2008 21:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to the same dest...
CVE-2007-6694
- EPSS 1.44%
- Veröffentlicht 29.01.2008 20:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The chrp_show_cpuinfo function (chrp/setup.c) in Linux kernel 2.4.21 through 2.6.18-53, when running on PowerPC, might allow local users to cause a denial of service (crash) via unknown vectors that cause the of_get_property function to fail, which t...
CVE-2008-0352
- EPSS 5.89%
- Veröffentlicht 18.01.2008 00:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6 packet, possibly involving the Jumbo Payload hop-by-hop option (jumbogram).