VYPR

Linux Kernel

by Ubuntu

Source repositories

CVEs (180)

  • CVE-2005-3044Sep 22, 2005
    risk 0.00cvss —epss 0.00

    Multiple vulnerabilities in Linux kernel before 2.6.13.2 allow local users to cause a denial of service (kernel OOPS from null dereference) via (1) fput in a 32-bit ioctl on 64-bit x86 systems or (2) sockfd_put in the 32-bit routing_ioctl function on 64-bit systems.

  • CVE-2005-2617Aug 17, 2005
    risk 0.00cvss —epss 0.00

    The syscall32_setup_pages function in syscall32.c for Linux kernel 2.6.12 and later, on the 64-bit x86 platform, does not check the return value of the insert_vm_struct function, which allows local users to trigger a memory leak via a 32-bit application with crafted ELF headers.

  • CVE-2005-0749Apr 1, 2005
    risk 0.00cvss —epss 0.00

    The load_elf_library in the Linux kernel before 2.6.11.6 allows local users to cause a denial of service (kernel crash) via a crafted ELF library or executable, which causes a free of an invalid pointer.

  • CVE-2004-0592Dec 31, 2004
    risk 0.00cvss —epss 0.02

    The tcp_find_option function of the netfilter subsystem for IPv6 in the SUSE Linux 2.6.5 kernel with USAGI patches, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that…

  • CVE-2004-0565Dec 6, 2004
    risk 0.00cvss —epss 0.00

    Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.

  • CVE-2004-0626Dec 6, 2004
    risk 0.00cvss —epss 0.03

    The tcp_find_option function of the netfilter subsystem in Linux kernel 2.6, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a…

  • CVE-2004-0394Aug 18, 2004
    risk 0.00cvss —epss 0.00

    A "potential" buffer overflow exists in the panic() function in Linux 2.4.x, although it may not be exploitable due to the functionality of panic.

  • CVE-2004-0001Feb 17, 2004
    risk 0.00cvss —epss 0.00

    Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.

  • CVE-2003-0984Jan 5, 2004
    risk 0.00cvss —epss 0.00

    Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space.

  • CVE-2003-0699Aug 27, 2003
    risk 0.00cvss —epss 0.02

    The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access userspace, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0700.

  • CVE-2003-0552Aug 27, 2003
    risk 0.00cvss —epss 0.03

    Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose source addresses are the same as the target.

  • CVE-2003-0465Aug 18, 2003
    risk 0.00cvss —epss 0.02

    The kernel strncpy function in Linux 2.4 and 2.5 does not %NUL pad the buffer on architectures other than x86, as opposed to the expected behavior of strncpy as implemented in libc, which could lead to information leaks.

  • CVE-2003-0643Jul 25, 2003
    risk 0.00cvss —epss 0.00

    Integer signedness error in the Linux Socket Filter implementation (filter.c) in Linux 2.4.3-pre3 to 2.4.22-pre10 allows attackers to cause a denial of service (crash).

  • CVE-2003-0418Jul 24, 2003
    risk 0.00cvss —epss 0.03

    The Linux 2.0 kernel IP stack does not properly calculate the size of an ICMP citation, which causes it to include portions of unauthorized memory in ICMP error responses.

  • CVE-2002-1572Dec 31, 2002
    risk 0.00cvss —epss 0.02

    Signed integer overflow in the bttv_read function in the bttv driver (bttv-driver.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors.

  • CVE-2002-1573Dec 31, 2002
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the pcilynx ieee1394 firewire driver (pcilynx.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors, related to "wrap handling."

  • CVE-2002-1319Dec 11, 2002
    risk 0.00cvss —epss 0.00

    The Linux kernel 2.4.20 and earlier, and 2.5.x, when running on x86 systems, allows local users to cause a denial of service (hang) via the emulation mode, which does not properly clear TF and NT EFLAGs.

  • CVE-2002-0429Aug 12, 2002
    risk 0.00cvss —epss 0.00

    The iBCS routines in arch/i386/kernel/traps.c for Linux kernels 2.4.18 and earlier on x86 systems allow local users to kill arbitrary processes via a a binary compatibility interface (lcall).

  • CVE-2001-0851Dec 6, 2001
    risk 0.00cvss —epss 0.03

    Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie.

  • CVE-1999-1341Oct 22, 1999
    risk 0.00cvss —epss 0.00

    Linux kernel before 2.3.18 or 2.2.13pre15, with SLIP and PPP options, allows local unprivileged users to forge IP packets via the TIOCSETD option on tty devices.

Page 9 of 9