VYPR

Kernel

by Linux

Source repositories

CVEs (18,581)

  • CVE-2006-2446Aug 15, 2006
    risk 0.00cvss epss 0.03

    Race condition between the kfree_skb and __skb_unlink functions in the socket buffer handling in Linux kernel 2.6.9, and possibly other versions, allows remote attackers to cause a denial of service (crash), as demonstrated using the TCP stress tests from the LTP test suite.

  • CVE-2006-3634Aug 4, 2006
    risk 0.00cvss epss 0.00

    The (1) __futex_atomic_op and (2) futex_atomic_cmpxchg_inatomic functions in Linux kernel 2.6.17-rc4 to 2.6.18-rc2 perform the atomic futex operation in the kernel address space instead of the user address space, which allows local users to cause a denial of service (crash).

  • CVE-2006-3626Jul 18, 2006
    risk 0.00cvss epss 0.02

    Race condition in Linux kernel 2.6.17.4 and earlier allows local users to gain root privileges by using prctl with PR_SET_DUMPABLE in a way that causes /proc/self/environ to become setuid root.

  • CVE-2006-2936Jul 10, 2006
    risk 0.00cvss epss 0.03

    The ftdi_sio driver (usb/serial/ftdi_sio.c) in Linux kernel 2.6.x up to 2.6.17, and possibly later versions, allows local users to cause a denial of service (memory consumption) by writing more data to the serial port than the hardware can handle, which causes the data to be…

  • CVE-2006-2935Jul 5, 2006
    risk 0.00cvss epss 0.01

    The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16, and later versions, assigns the wrong value to a length variable, which allows local users to execute arbitrary code via a crafted USB Storage device that triggers a buffer…

  • CVE-2006-2934Jun 30, 2006
    risk 0.00cvss epss 0.05

    SCTP conntrack (ip_conntrack_proto_sctp.c) in netfilter for Linux kernel 2.6.17 before 2.6.17.3 and 2.6.16 before 2.6.16.23 allows remote attackers to cause a denial of service (crash) via a packet without any chunks, which causes a variable to contain an invalid value that is…

  • CVE-2006-0456Jun 27, 2006
    risk 0.00cvss epss 0.00

    The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors.

  • CVE-2006-2448Jun 23, 2006
    risk 0.00cvss epss 0.00

    Linux kernel before 2.6.16.21 and 2.6.17, when running on PowerPC, does not perform certain required access_ok checks, which allows local users to read arbitrary kernel memory on 64-bit systems (signal_64.c) and cause a denial of service (crash) and possibly read kernel memory…

  • CVE-2006-2445Jun 23, 2006
    risk 0.00cvss epss 0.00

    Race condition in run_posix_cpu_timers in Linux kernel before 2.6.16.21 allows local users to cause a denial of service (BUG_ON crash) by causing one CPU to attach a timer to a process that is exiting.

  • CVE-2006-3085Jun 23, 2006
    risk 0.00cvss epss 0.03

    xt_sctp in netfilter for Linux kernel before 2.6.17.1 allows attackers to cause a denial of service (infinite loop) via an SCTP chunk with a 0 length.

  • CVE-2006-1862May 24, 2006
    risk 0.00cvss epss 0.00

    The virtual memory implementation in Linux kernel 2.6.x allows local users to cause a denial of service (panic) by running lsof a large number of times in a way that produces a heavy system load.

  • CVE-2006-1858May 22, 2006
    risk 0.00cvss epss 0.06

    SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a chunk length that is inconsistent with the actual length of provided parameters.

  • CVE-2006-1856May 19, 2006
    risk 0.00cvss epss 0.03

    Certain modifications to the Linux kernel 2.6.16 and earlier do not add the appropriate Linux Security Modules (LSM) file_permission hooks to the (1) readv and (2) writev functions, which might allow attackers to bypass intended access restrictions.

  • CVE-2006-0039May 19, 2006
    risk 0.00cvss epss 0.00

    Race condition in the do_add_counters function in netfilter for Linux kernel 2.6.16 allows local users with CAP_NET_ADMIN capabilities to read kernel memory by triggering the race condition in a way that produces a size value that is inconsistent with allocated memory, which…

  • CVE-2006-1528May 18, 2006
    risk 0.00cvss epss 0.00

    Linux kernel before 2.6.13 allows local users to cause a denial of service (crash) via a dio transfer from the sg driver to memory mapped (mmap) IO space.

  • CVE-2006-1855May 18, 2006
    risk 0.00cvss epss 0.00

    choose_new_parent in Linux kernel before 2.6.11.12 includes certain debugging code, which allows local users to cause a denial of service (panic) by causing certain circumstances involving termination of a parent process.

  • CVE-2006-1860May 12, 2006
    risk 0.00cvss epss 0.00

    lease_init in fs/locks.c in Linux kernel before 2.6.16.16 allows attackers to cause a denial of service (fcntl_setlease lockup) via actions that cause lease_init to free a lock that might not have been allocated on the stack.

  • CVE-2006-1859May 12, 2006
    risk 0.00cvss epss 0.00

    Memory leak in __setlease in fs/locks.c in Linux kernel before 2.6.16.16 allows attackers to cause a denial of service (memory consumption) via unspecified actions related to an "uninitialised return value," aka "slab leak."

  • CVE-2006-2274May 9, 2006
    risk 0.00cvss epss 0.04

    Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (infinite recursion and crash) via a packet that contains two or more DATA fragments, which causes an skb pointer to refer back to itself when the full message is reassembled, leading to…

  • CVE-2006-2271May 9, 2006
    risk 0.00cvss epss 0.04

    The ECNE chunk handling in Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via an unexpected chunk when the session is in CLOSED state.

Page 916 of 930