Vulnerabilities > Linux > Linux Kernel > 2.3.0

DATE CVE VULNERABILITY TITLE RISK
2005-01-21 CVE-2004-1057 Unspecified vulnerability in Linux Kernel Device Driver Virtual Memory Flags
Multiple drivers in Linux kernel 2.4.19 and earlier do not properly mark memory with the VM_IO flag, which causes incorrect reference counts and may lead to a denial of service (kernel panic) when accessing freed kernel pages.
local
low complexity
linux redhat
7.2
2004-12-31 CVE-2004-2013 Integer Overflow or Wraparound vulnerability in Linux Kernel
Integer overflow in the SCTP_SOCKOPT_DEBUG_NAME SCTP socket option in socket.c in the Linux kernel 2.4.25 and earlier allows local users to execute arbitrary code via an optlen value of -1, which causes kmalloc to allocate 0 bytes of memory.
local
low complexity
linux CWE-190
7.8
2004-12-23 CVE-2004-0816 Integer Underflow (Wrap or Wraparound) vulnerability in Linux Kernel
Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service (application crash) via a malformed IP packet.
network
low complexity
linux CWE-191
7.5
2004-12-23 CVE-2004-0685 Information Disclosure vulnerability in Linux Kernel USB Driver Uninitialized Structure
Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous usage.
local
low complexity
linux redhat trustix
4.6
2004-03-03 CVE-2004-0003 Privilege Escalation vulnerability in Linux Kernel R128 Device Driver
Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."
local
low complexity
linux
4.6
2003-12-15 CVE-2003-0961 Unspecified vulnerability in Linux Kernel
Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges.
local
low complexity
linux
7.2
2003-08-27 CVE-2003-0619 Unspecified vulnerability in Linux Kernel
Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call.
network
low complexity
linux
5.0
2002-12-31 CVE-2002-1976 Unspecified vulnerability in Linux Kernel
ifconfig, when used on the Linux kernel 2.2 and later, does not report when the network interface is in promiscuous mode if it was put in promiscuous mode using PACKET_MR_PROMISC, which could allow attackers to sniff the network without detection, as demonstrated using libpcap.
local
low complexity
linux
2.1
2002-08-12 CVE-2002-0499 Unspecified vulnerability in Linux Kernel
The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.
local
low complexity
linux
2.1
1999-10-22 CVE-1999-1341 Unspecified vulnerability in Linux Kernel
Linux kernel before 2.3.18 or 2.2.13pre15, with SLIP and PPP options, allows local unprivileged users to forge IP packets via the TIOCSETD option on tty devices.
local
low complexity
linux
4.6