VYPR

Kernel

by Linux

Source repositories

CVEs (20,896)

  • CVE-2004-2135May 26, 2004
    risk 0.03cvss —epss 0.01

    cryptoloop on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decryption.

  • CVE-2004-0186Mar 15, 2004
    risk 0.03cvss —epss 0.02

    smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.

  • CVE-2004-0077Mar 3, 2004
    risk 0.03cvss —epss 0.02

    The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root…

  • CVE-2003-0985Jan 20, 2004
    risk 0.03cvss —epss 0.01

    The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual…

  • CVE-2003-0961Dec 15, 2003
    risk 0.03cvss —epss 0.03

    Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges.

  • CVE-2003-0462Aug 27, 2003
    risk 0.03cvss —epss 0.01

    A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).

  • CVE-2003-0501Aug 7, 2003
    risk 0.03cvss —epss 0.01

    The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries.

  • CVE-2003-0127Mar 31, 2003
    risk 0.03cvss —epss 0.02

    The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.

  • CVE-2002-1380Dec 23, 2002
    risk 0.03cvss —epss 0.01

    Linux kernel 2.2.x allows local users to cause a denial of service (crash) by using the mmap() function with a PROT_READ parameter to access non-readable memory pages through the /proc/pid/mem interface.

  • CVE-2002-0499Aug 12, 2002
    risk 0.03cvss —epss 0.01

    The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.

  • CVE-2001-1384Oct 18, 2001
    risk 0.03cvss —epss 0.01

    ptrace in Linux 2.2.x through 2.2.19, and 2.4.x through 2.4.9, allows local users to gain root privileges by running ptrace on a setuid or setgid program that itself calls an unprivileged program, such as newgrp.

  • CVE-2001-0907Oct 18, 2001
    risk 0.03cvss —epss 0.01

    Linux kernel 2.2.1 through 2.2.19, and 2.4.1 through 2.4.10, allows local users to cause a denial of service via a series of deeply nested symlinks, which causes the kernel to spend extra time when trying to access the link.

  • CVE-2001-0317May 3, 2001
    risk 0.03cvss —epss 0.01

    Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process.

  • CVE-2001-0316May 3, 2001
    risk 0.03cvss —epss 0.01

    Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call.

  • CVE-2000-0227Mar 23, 2000
    risk 0.03cvss —epss 0.01

    The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max parameter, which allows local users to cause a denial of service by requesting a large number of sockets.

  • CVE-1999-0986Dec 8, 1999
    risk 0.03cvss —epss 0.04

    The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.

  • CVE-1999-0720Aug 23, 1999
    risk 0.03cvss —epss 0.01

    The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users.

  • CVE-1999-1166Jul 11, 1999
    risk 0.03cvss —epss 0.01

    Linux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by accessing and modifying kernel memory.

  • CVE-1999-0804Jun 1, 1999
    risk 0.03cvss —epss 0.06

    Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.

  • CVE-1999-0381Feb 26, 1999
    risk 0.03cvss —epss 0.01

    super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access.

Page 804 of 1,045