CVE-2004-2607
- EPSS 0.06%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
A numeric casting discrepancy in sdla_xfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users to read portions of kernel memory via a large len argument, which is received as an int but cast to a short, which prevents a rea...
CVE-2004-2660
- EPSS 0.05%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Memory leak in direct-io.c in Linux kernel 2.6.x before 2.6.10 allows local users to cause a denial of service (memory consumption) via certain O_DIRECT (direct IO) write requests.
CVE-2004-2731
- EPSS 0.14%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Multiple integer overflows in Sbus PROM driver (drivers/sbus/char/openprom.c) for the Linux kernel 2.4.x up to 2.4.27, 2.6.x up to 2.6.7, and possibly later versions, allow local users to execute arbitrary code by specifying (1) a small buffer size t...
CVE-2004-0685
- EPSS 0.15%
- Veröffentlicht 23.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous usage.
CVE-2004-0814
- EPSS 0.24%
- Veröffentlicht 23.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote a...
CVE-2004-0816
- EPSS 7.37%
- Veröffentlicht 23.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service (application crash) via a malformed IP packet.
CVE-2004-1333
- EPSS 0.23%
- Veröffentlicht 15.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a buffer overflow.
CVE-2004-1335
- EPSS 0.29%
- Veröffentlicht 15.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory consumption) by repeatedly calling the ip_cmsg_send function.
CVE-2004-0496
- EPSS 0.06%
- Veröffentlicht 06.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities than those identified in CVE-2004-0495, as found by the Sparse source code checking tool.
CVE-2004-0497
- EPSS 0.31%
- Veröffentlicht 06.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.