CVE-2008-4933
- EPSS 2.9%
- Veröffentlicht 05.11.2008 15:00:14
- Zuletzt bearbeitet 16.06.2026 22:58:47
Buffer overflow in the hfsplus_find_cat function in fs/hfsplus/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfsplus filesystem image with an invalid catalog n...
CVE-2008-4934
- EPSS 3.29%
- Veröffentlicht 05.11.2008 15:00:14
- Zuletzt bearbeitet 16.06.2026 22:58:47
The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (syste...
CVE-2008-4618
- EPSS 2.66%
- Veröffentlicht 21.10.2008 00:10:53
- Zuletzt bearbeitet 16.06.2026 22:58:10
The Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.27 does not properly handle a protocol violation in which a parameter has an invalid length, which allows attackers to cause a denial of service (panic) via...
CVE-2008-3831
- EPSS 0.51%
- Veröffentlicht 20.10.2008 17:59:26
- Zuletzt bearbeitet 16.06.2026 22:56:37
The i915 driver in (1) drivers/char/drm/i915_dma.c in the Linux kernel 2.6.24 on Debian GNU/Linux and (2) sys/dev/pci/drm/i915_drv.c in OpenBSD does not restrict the DRM_I915_HWS_ADDR ioctl to the Direct Rendering Manager (DRM) master, which allows l...
CVE-2008-4609
- EPSS 32.12%
- Veröffentlicht 20.10.2008 17:59:26
- Zuletzt bearbeitet 16.06.2026 22:58:09
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vect...
CVE-2008-4554
- EPSS 0.39%
- Veröffentlicht 15.10.2008 20:07:42
- Zuletzt bearbeitet 16.06.2026 22:58:03
The do_splice_from function in fs/splice.c in the Linux kernel before 2.6.27 does not reject file descriptors that have the O_APPEND flag set, which allows local users to bypass append mode and make arbitrary changes to other locations in the file.
CVE-2008-4576
- EPSS 3.68%
- Veröffentlicht 15.10.2008 20:07:42
- Zuletzt bearbeitet 16.06.2026 22:58:05
sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active transports and triggers the O...
CVE-2008-4445
- EPSS 0.45%
- Veröffentlicht 06.10.2008 19:54:36
- Zuletzt bearbeitet 16.06.2026 22:57:49
The sctp_auth_ep_set_hmacs function in net/sctp/auth.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, does not verify that the identifier index is within...
CVE-2008-3833
- EPSS 0.42%
- Veröffentlicht 03.10.2008 17:41:40
- Zuletzt bearbeitet 16.06.2026 22:56:37
The generic_file_splice_write function in fs/splice.c in the Linux kernel before 2.6.19 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain s...
CVE-2008-4410
- EPSS 0.38%
- Veröffentlicht 03.10.2008 17:41:40
- Zuletzt bearbeitet 16.06.2026 22:57:45
The vmi_write_ldt_entry function in arch/x86/kernel/vmi_32.c in the Virtual Machine Interface (VMI) in the Linux kernel 2.6.26.5 invokes write_idt_entry where write_ldt_entry was intended, which allows local users to cause a denial of service (persis...