CVE-2008-3276
- EPSS 3.21%
- Veröffentlicht 18.08.2008 17:41:00
- Zuletzt bearbeitet 16.06.2026 22:55:31
Integer overflow in the dccp_setsockopt_change function in net/dccp/proto.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.17-rc1 through 2.6.26.2 allows remote attackers to cause a denial of service (panic) via ...
CVE-2008-3686
- EPSS 0.47%
- Veröffentlicht 14.08.2008 22:41:00
- Zuletzt bearbeitet 16.06.2026 22:56:18
The rt6_fill_node function in net/ipv6/route.c in Linux kernel 2.6.26-rc4, 2.6.26.2, and possibly other 2.6.26 versions, allows local users to cause a denial of service (kernel OOPS) via IPv6 requests when no IPv6 input device is in use, which trigge...
CVE-2008-3275
- EPSS 0.51%
- Veröffentlicht 12.08.2008 23:41:00
- Zuletzt bearbeitet 16.06.2026 22:55:31
The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denia...
CVE-2008-3534
- EPSS 0.53%
- Veröffentlicht 08.08.2008 19:41:00
- Zuletzt bearbeitet 16.06.2026 22:56:00
The shmem_delete_inode function in mm/shmem.c in the tmpfs implementation in the Linux kernel before 2.6.26.1 allows local users to cause a denial of service (system crash) via a certain sequence of file create, remove, and overwrite operations, as d...
CVE-2008-3535
- EPSS 0.53%
- Veröffentlicht 08.08.2008 19:41:00
- Zuletzt bearbeitet 16.06.2026 22:56:00
Off-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-rc2 allows local users to cause a denial of service (system crash) via a certain sequence of file I/O operations with readv and writev, as demonstrate...
CVE-2008-3272
- EPSS 0.42%
- Veröffentlicht 08.08.2008 18:41:00
- Zuletzt bearbeitet 16.06.2026 22:55:30
The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain da...
- EPSS 3.28%
- Veröffentlicht 06.08.2008 18:41:00
- Zuletzt bearbeitet 16.06.2026 22:55:55
Buffer overflow in format descriptor parsing in the uvc_parse_format function in drivers/media/video/uvc/uvc_driver.c in uvcvideo in the video4linux (V4L) implementation in the Linux kernel before 2.6.26.1 has unknown impact and attack vectors.
CVE-2008-3247
- EPSS 0.36%
- Veröffentlicht 24.07.2008 15:41:00
- Zuletzt bearbeitet 16.06.2026 22:55:27
The LDT implementation in the Linux kernel 2.6.25.x before 2.6.25.11 on x86_64 platforms uses an incorrect size for ldt_desc, which allows local users to cause a denial of service (system crash) or possibly gain privileges via unspecified vectors.
CVE-2008-2931
- EPSS 0.38%
- Veröffentlicht 09.07.2008 18:41:00
- Zuletzt bearbeitet 16.06.2026 22:54:45
The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of ...
CVE-2008-2812
- EPSS 0.43%
- Veröffentlicht 09.07.2008 00:41:00
- Zuletzt bearbeitet 16.06.2026 22:54:32
The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) ha...