Vulnerabilities > Linux > Linux Kernel > Medium

DATE CVE VULNERABILITY TITLE RISK
2004-12-06 CVE-2004-0626 The tcp_find_option function of the netfilter subsystem in Linux kernel 2.6, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type.
network
low complexity
conectiva gentoo linux suse
5.0
2004-08-18 CVE-2004-0229 Unspecified vulnerability in Linux kernel Framebuffer Code
The framebuffer driver in Linux kernel 2.6.x does not properly use the fb_copy_cmap function, with unknown impact.
local
low complexity
gentoo linux
4.6
2004-06-01 CVE-2004-0109 Buffer Overflow vulnerability in Linux Kernel 2.4.0/2.5.0/2.6.0
Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.
local
low complexity
linux
4.6
2004-03-03 CVE-2004-0003 Privilege Escalation vulnerability in Linux Kernel R128 Device Driver
Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."
local
low complexity
linux
4.6
2004-03-03 CVE-2002-1574 Unspecified vulnerability in Linux Kernel
Buffer overflow in the ixj telephony card driver in Linux before 2.4.20 has unknown impact and attack vectors.
local
low complexity
linux
4.6
2004-01-05 CVE-2003-0984 Unspecified vulnerability in Linux Kernel
Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space.
local
low complexity
linux
4.6
2003-12-31 CVE-2003-1467 Cross-Site Scripting vulnerability in Phorum
Multiple cross-site scripting (XSS) vulnerabilities in (1) login.php, (2) register.php, (3) post.php, and (4) common.php in Phorum before 3.4.3 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
4.3
2003-12-31 CVE-2003-1454 Unspecified vulnerability in Invision Power Services Invision Board 1.0/1.0.1/1.1.1
Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator password in a cookie in plaintext, which could allow remote attackers to gain access.
network
low complexity
linux microsoft unix invision-power-services
5.0
2003-12-31 CVE-2003-1430 Path Traversal vulnerability in Epic Games Unreal Engine 226F/433/436
Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL.
network
low complexity
linux microsoft epic-games CWE-22
5.0
2003-12-31 CVE-2003-1428 Unspecified vulnerability in Bharat Mediratta Gallery 1.3.3
Gallery 1.3.3 creates directories with insecure permissions, which allows local users to read, modify, or delete photos.
low complexity
linux bharat-mediratta
4.8