Vulnerabilities > Linux > Linux Kernel > 2.6.16.12

DATE CVE VULNERABILITY TITLE RISK
2006-06-23 CVE-2006-3085 Remote Denial of Service vulnerability in Linux Kernel XT_SCTP-netfilter
xt_sctp in netfilter for Linux kernel before 2.6.17.1 allows attackers to cause a denial of service (infinite loop) via an SCTP chunk with a 0 length.
network
low complexity
linux
7.8
2006-05-27 CVE-2006-2629 Local Denial of Service vulnerability in Linux Kernel Proc dentry_unused Corruption
Race condition in Linux kernel 2.6.15 to 2.6.17, when running on SMP platforms, allows local users to cause a denial of service (crash) by creating and exiting a large number of tasks, then accessing the /proc entry of a task that is exiting, which causes memory corruption that leads to a failure in the prune_dcache function or a BUG_ON error in include/linux/list.h.
local
high complexity
linux
4.0
2006-05-22 CVE-2006-1858 Improper Input Validation vulnerability in Linux Kernel
SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a chunk length that is inconsistent with the actual length of provided parameters.
network
low complexity
linux CWE-20
7.8
2006-05-22 CVE-2006-1857 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Linux Kernel
Buffer overflow in SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed HB-ACK chunk.
network
low complexity
linux CWE-119
critical
9.0
2006-05-05 CVE-2006-1052 Local Denial of Service vulnerability in Linux Kernel SELinux_PTrace
The selinux_ptrace logic in hooks.c in SELinux for Linux 2.6.6 allows local users with ptrace permissions to change the tracer SID to an SID of another process.
local
low complexity
linux
2.1
2006-05-03 CVE-2006-1527 Remote Denial of Service vulnerability in Linux Kernel 2.6.16.12
The SCTP-netfilter code in Linux kernel before 2.6.16.13 allows remote attackers to trigger a denial of service (infinite loop) via unknown vectors that cause an invalid SCTP chunk size to be processed by the for_each_sctp_chunk function.
network
low complexity
linux
5.0