Vulnerabilities > Linux > Linux Kernel > 2.6.3

DATE CVE VULNERABILITY TITLE RISK
2005-03-07 CVE-2005-0180 Integer Overflow vulnerability in Linux Kernel SCSI IOCTL
Multiple integer signedness errors in the sg_scsi_ioctl function in scsi_ioctl.c for Linux 2.6.x allow local users to read or modify kernel memory via negative integers in arguments to the scsi ioctl, which bypass a maximum length check before calling the copy_from_user and copy_to_user functions.
local
low complexity
linux
3.6
2005-03-07 CVE-2005-0179 Unspecified vulnerability in Linux Kernel
Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.
local
low complexity
linux
2.1
2005-03-01 CVE-2004-0986 Iptables before 1.2.11, under certain conditions, does not properly load the required modules at system startup, which causes the firewall rules to fail to load and protect the system from remote attackers.
network
low complexity
suse debian linux redhat
7.5
2005-01-27 CVE-2004-0887 Local Privilege Escalation vulnerability in Linux IBM S/390 Kernel SACF Instruction
SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a certain privileged instruction, which allows local users to gain root privileges.
local
low complexity
linux suse
7.2
2005-01-10 CVE-2004-1137 Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers to cause a denial of service or execute arbitrary code via (1) the ip_mc_source function, which decrements a counter to -1, or (2) the igmp_marksources function, which does not properly validate IGMP message parameters and performs an out-of-bounds read.
network
low complexity
linux ubuntu
critical
10.0
2005-01-10 CVE-2004-1074 Local Denial Of Service And Memory Disclosure vulnerability in Linux Kernel
The binfmt functionality in the Linux kernel, when "memory overcommit" is enabled, allows local users to cause a denial of service (kernel oops) via a malformed a.out binary.
local
low complexity
linux redhat suse trustix turbolinux
2.1
2005-01-10 CVE-2004-1073 Local Privilege Escalation vulnerability in Linux Kernel BINFMT_ELF Loader
The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, allows local users to read non-readable ELF binaries by using the interpreter (PT_INTERP) functionality.
local
low complexity
linux redhat suse trustix turbolinux
2.1
2005-01-10 CVE-2004-1072 Local Privilege Escalation vulnerability in Linux Kernel BINFMT_ELF Loader
The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL terminated, which could cause strings longer than PATH_MAX to be used, leading to buffer overflows that allow local users to cause a denial of service (hang) and possibly execute arbitrary code.
local
low complexity
linux redhat suse trustix turbolinux
7.2
2005-01-10 CVE-2004-1071 Local Privilege Escalation vulnerability in Linux Kernel BINFMT_ELF Loader
The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly handle a failed call to the mmap function, which causes an incorrect mapped image and may allow local users to execute arbitrary code.
local
low complexity
linux redhat suse trustix turbolinux
7.2
2005-01-10 CVE-2004-1070 Local Privilege Escalation vulnerability in Linux Kernel BINFMT_ELF Loader
The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code.
local
low complexity
linux redhat suse trustix turbolinux
7.2