Vulnerabilities > Linux > Linux Kernel > 2.4.36.6

DATE CVE VULNERABILITY TITLE RISK
2008-10-15 CVE-2008-4576 Improper Authentication vulnerability in Linux Kernel
sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active transports and triggers the OOPS when the T1-Init timer expires.
network
low complexity
linux CWE-287
7.8
2007-09-14 CVE-2007-3740 Permissions, Privileges, and Access Controls vulnerability in Linux Kernel
The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges.
local
linux CWE-264
4.4
2005-11-20 CVE-2005-2709 Resource Management Errors vulnerability in Linux Kernel
The sysctl functionality (sysctl.c) in Linux kernel before 2.6.14.1 allows local users to cause a denial of service (kernel oops) and possibly execute code by opening an interface file in /proc/sys/net/ipv4/conf/, waiting until the interface is unregistered, then obtaining and modifying function pointers in memory that was used for the ctl_table.
local
low complexity
linux CWE-399
4.6