Vulnerabilities > Linux > Linux Kernel > High

DATE CVE VULNERABILITY TITLE RISK
2005-11-25 CVE-2005-3810 Denial-Of-Service vulnerability in kernel
ip_conntrack_proto_icmp.c in ctnetlink in Linux kernel 2.6.14 up to 2.6.14.3 allows attackers to cause a denial of service (kernel oops) via a message without ICMP ID (ICMP_ID) information, which leads to a null dereference.
network
low complexity
linux
7.8
2005-11-25 CVE-2005-3809 Denial-Of-Service vulnerability in kernel
The nfattr_to_tcp function in ip_conntrack_proto_tcp.c in ctnetlink in Linux kernel 2.6.14 up to 2.6.14.3 allows attackers to cause a denial of service (kernel oops) via an update message without private protocol information, which triggers a null dereference.
network
low complexity
linux
7.8
2005-11-22 CVE-2005-3753 Denial-Of-Service vulnerability in kernel
Linux kernel before after 2.6.12 and before 2.6.13.1 might allow attackers to cause a denial of service (Oops) via certain IPSec packets that cause alignment problems in standard multi-block cipher processors.
network
low complexity
linux
7.8
2005-09-06 CVE-2005-2801 Incorrect Comparison vulnerability in Linux Kernel 2.6.0
xattr.c in the ext2 and ext3 file system code for Linux kernel 2.6 does not properly compare the name_index fields when sharing xattr blocks, which could prevent default ACLs from being applied.
network
low complexity
linux CWE-697
7.5
2005-05-17 CVE-2005-1589 Local Memory Corruption vulnerability in Multiple Linux Kernel IOCTL Handlers
The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space and allows local users to cause a denial of service and possibly execute arbitrary code, a similar vulnerability to CVE-2005-1264.
local
low complexity
linux
7.2
2005-05-17 CVE-2005-1264 Local Memory Corruption vulnerability in Multiple Linux Kernel IOCTL Handlers
Raw character devices (raw.c) in the Linux kernel 2.6.x call the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space, a similar vulnerability to CVE-2005-1589.
local
low complexity
linux
7.2
2005-05-11 CVE-2005-1263 Local Buffer Overflow vulnerability in Linux Kernel ELF Core Dump
The elf_core_dump function in binfmt_elf.c for Linux kernel 2.x.x to 2.2.27-rc2, 2.4.x to 2.4.31-pre1, and 2.6.x to 2.6.12-rc4 allows local users to execute arbitrary code via an ELF binary that, in certain conditions involving the create_elf_tables function, causes a negative length argument to pass a signed integer comparison, leading to a buffer overflow.
local
low complexity
linux
7.2
2005-05-02 CVE-2005-0867 Unspecified vulnerability in Linux Kernel 2.6.0
Integer overflow in Linux kernel 2.6 allows local users to overwrite kernel memory by writing to a sysfs file.
local
low complexity
linux
7.2
2005-05-02 CVE-2005-0449 Improper Input Validation vulnerability in Linux Kernel
The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are not properly handled by the skb_checksum_help function.
network
linux CWE-20
7.1
2005-05-02 CVE-2005-0209 Improper Input Validation vulnerability in Linux Kernel 2.6.8.1
Netfilter in Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via crafted IP packet fragments.
network
low complexity
linux CWE-20
7.8