CVE-2007-5904
- EPSS 1.97%
- Veröffentlicht 09.11.2007 18:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple buffer overflows in CIFS VFS in Linux kernel 2.6.23 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SMB responses that trigger the overflows in the SendReceive function.
CVE-2007-4997
- EPSS 5.39%
- Veröffentlicht 06.11.2007 19:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer underflow in the ieee80211_rx function in net/ieee80211/ieee80211_rx.c in the Linux kernel 2.6.x before 2.6.23 allows remote attackers to cause a denial of service (crash) via a crafted SKB length value in a runt IEEE 802.11 frame when the IE...
CVE-2007-3850
- EPSS 0.1%
- Veröffentlicht 23.10.2007 10:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The eHCA driver in Linux kernel 2.6 before 2.6.22, when running on PowerPC, does not properly map userspace resources, which allows local users to read portions of physical address space.
CVE-2007-4133
- EPSS 0.1%
- Veröffentlicht 04.10.2007 23:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The (1) hugetlb_vmtruncate_list and (2) hugetlb_vmtruncate functions in fs/hugetlbfs/inode.c in the Linux kernel before 2.6.19-rc4 perform certain prio_tree calculations using HPAGE_SIZE instead of PAGE_SIZE units, which allows local users to cause a...
- EPSS 0.06%
- Veröffentlicht 26.09.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The disconnect method in the Philips USB Webcam (pwc) driver in Linux kernel 2.6.x before 2.6.22.6 "relies on user space to close the device," which allows user-assisted local attackers to cause a denial of service (USB subsystem hang and CPU consump...
CVE-2007-4571
- EPSS 0.19%
- Veröffentlicht 26.09.2007 10:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux kernel before 2.6.22.8 does not return the correct write size, which allows local users to obtain sensitive information (kernel memor...
CVE-2007-5087
- EPSS 0.11%
- Veröffentlicht 26.09.2007 10:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ATM module in the Linux kernel before 2.4.35.3, when CLIP support is enabled, allows local users to cause a denial of service (kernel panic) by reading /proc/net/atm/arp before the CLIP module has been loaded.
CVE-2007-4573
- EPSS 0.42%
- Veröffentlicht 24.09.2007 22:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users t...
CVE-2007-0997
- EPSS 0.04%
- Veröffentlicht 18.09.2007 19:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Race condition in the tee (sys_tee) system call in the Linux kernel 2.6.17 through 2.6.17.6 might allow local users to cause a denial of service (system crash), obtain sensitive information (kernel memory contents), or gain privileges via unspecified...
CVE-2007-3731
- EPSS 0.11%
- Veröffentlicht 17.09.2007 17:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Linux kernel 2.6.20 and 2.6.21 does not properly handle an invalid LDT segment selector in %cs (the xcs field) during ptrace single-step operations, which allows local users to cause a denial of service (NULL dereference and OOPS) via certain cod...