Vulnerabilities > Linux > Linux Kernel > High

DATE CVE VULNERABILITY TITLE RISK
2007-12-18 CVE-2007-6417 Resource Management Errors vulnerability in Linux Kernel
The shmem_getpage function (mm/shmem.c) in Linux kernel 2.6.11 through 2.6.23 does not properly clear allocated memory in some rare circumstances related to tmpfs, which might allow local users to read sensitive kernel data or cause a denial of service (crash).
local
low complexity
linux CWE-399
7.2
2007-11-20 CVE-2007-6052 Privilege Escalation vulnerability in IBM DB2
IBM DB2 UDB 9.1 before Fixpak 4 does not properly perform vector aggregation, which might allow attackers to cause a denial of service (divide-by-zero error and DBMS crash), related to an "overflow." NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
network
low complexity
linux microsoft unix ibm
7.8
2007-11-20 CVE-2007-6050 Permissions, Privileges, and Access Controls vulnerability in IBM DB2 Universal Database
Unspecified vulnerability in DB2LICD in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, related to creation of an "insecure directory."
local
low complexity
linux microsoft unix ibm CWE-264
7.2
2007-11-20 CVE-2007-6049 Permissions, Privileges, and Access Controls vulnerability in IBM DB2 Universal Database
Unspecified vulnerability in the SSL LOAD GSKIT action in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, involving a call to dlopen when the effective uid is root.
local
low complexity
linux unix ibm CWE-264
7.2
2007-11-20 CVE-2007-6046 Privilege Escalation vulnerability in IBM DB2
Unspecified vulnerability in unspecified setuid programs in IBM DB2 UDB 9.1 before Fixpak 4 allows local users to have an unknown impact.
local
low complexity
linux microsoft unix ibm
7.2
2007-09-24 CVE-2007-4573 Permissions, Privileges, and Access Controls vulnerability in Linux Kernel
The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain privileges by triggering an out-of-bounds access to the system call table using the %RAX register.
local
low complexity
linux CWE-264
7.2
2007-09-18 CVE-2007-4938 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value.
7.6
2007-05-18 CVE-2007-2764 Improper Input Validation vulnerability in Linux Kernel
The embedded Linux kernel in certain Sun-Brocade SilkWorm switches before 20070516 does not properly handle a situation in which a non-root user creates a kernel process, which allows attackers to cause a denial of service (oops and device reboot) via unspecified vectors.
network
low complexity
linux brocade CWE-20
7.8
2007-04-11 CVE-2007-1945 Unspecified vulnerability in IBM Websphere Application Server
Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.
network
low complexity
hp ibm linux microsoft sun
7.5
2007-04-11 CVE-2007-1357 Denial Of Service vulnerability in Linux Kernel AppleTalk ATalk_Sum_SKB Function
The atalk_sum_skb function in AppleTalk for Linux kernel 2.6.x before 2.6.21, and possibly 2.4.x, allows remote attackers to cause a denial of service (crash) via an AppleTalk frame that is shorter than the specified length, which triggers a BUG_ON call when an attempt is made to perform a checksum.
network
low complexity
linux
7.8