Vulnerabilities > Linux > Linux Kernel > 2.2.20

DATE CVE VULNERABILITY TITLE RISK
2004-12-23 CVE-2004-0814 Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote attackers to cause a denial of service (panic) by switching from console to PPP line discipline, then quickly sending data that is received during the switch.
local
high complexity
linux ubuntu
1.2
2004-12-23 CVE-2004-0685 Information Disclosure vulnerability in Linux Kernel USB Driver Uninitialized Structure
Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous usage.
local
low complexity
linux redhat trustix
4.6
2004-03-03 CVE-2004-0077 Local Privilege Escalation vulnerability in Linux Kernel do_mremap Function VMA Limit
The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.
local
low complexity
redhat linux netwosix trustix
7.2
2004-03-03 CVE-2004-0003 Privilege Escalation vulnerability in Linux Kernel R128 Device Driver
Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."
local
low complexity
linux
4.6
2003-12-15 CVE-2003-0961 Unspecified vulnerability in Linux Kernel
Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges.
local
low complexity
linux
7.2
2003-08-27 CVE-2003-0619 Unspecified vulnerability in Linux Kernel
Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call.
network
low complexity
linux
5.0
2003-03-31 CVE-2003-0127 Unspecified vulnerability in Linux Kernel
The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.
local
low complexity
linux
7.2
2002-12-31 CVE-2002-1976 Unspecified vulnerability in Linux Kernel
ifconfig, when used on the Linux kernel 2.2 and later, does not report when the network interface is in promiscuous mode if it was put in promiscuous mode using PACKET_MR_PROMISC, which could allow attackers to sniff the network without detection, as demonstrated using libpcap.
local
low complexity
linux
2.1
2002-12-23 CVE-2002-1380 Local Denial of Service vulnerability in Linux Kernel 2.2 mmap()
Linux kernel 2.2.x allows local users to cause a denial of service (crash) by using the mmap() function with a PROT_READ parameter to access non-readable memory pages through the /proc/pid/mem interface.
local
low complexity
linux
2.1
2002-12-11 CVE-2002-1319 Denial Of Service vulnerability in Linux Kernel 2.4 System Call TF Flag
The Linux kernel 2.4.20 and earlier, and 2.5.x, when running on x86 systems, allows local users to cause a denial of service (hang) via the emulation mode, which does not properly clear TF and NT EFLAGs.
local
low complexity
linux trustix
2.1