Vulnerabilities > Linux

DATE CVE VULNERABILITY TITLE RISK
2008-09-03 CVE-2008-3901 Information Exposure vulnerability in Suspend2 Software Suspend 2 22.2.1
Software suspend 2 2-2.2.1, when used with the Linux kernel 2.6.16, stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.
local
low complexity
linux suspend2 CWE-200
2.1
2008-08-13 CVE-2008-3671 Cryptographic Issues vulnerability in Acronis True Image Echo Server 9.5.8072
Acronis True Image Echo Server 9.x build 8072 on Linux does not properly encrypt backups to an FTP server, which allows remote attackers to obtain sensitive information.
network
low complexity
linux acronis CWE-310
5.0
2008-08-12 CVE-2008-3275 Classic Buffer Overflow vulnerability in multiple products
The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denial of service ("overflow" of the UBIFS orphan area) via a series of attempted file creations within deleted directories.
local
low complexity
linux debian canonical suse CWE-120
5.5
2008-08-10 CVE-2008-3579 Improper Authentication vulnerability in Calacode Atmail 5.41
Calacode @Mail 5.41 on Linux does not require administrative authentication for build-plesk-upgrade.php, which allows remote attackers to obtain sensitive information by creating and downloading a backup archive of the entire @Mail directory tree.
network
low complexity
linux calacode CWE-287
7.8
2008-08-08 CVE-2008-3535 Off-By-One Error vulnerability in Linux Kernel
Off-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-rc2 allows local users to cause a denial of service (system crash) via a certain sequence of file I/O operations with readv and writev, as demonstrated by testcases/kernel/fs/ftest/ftest03 from the Linux Test Project.
local
low complexity
linux debian canonical CWE-193
4.9
2008-08-07 CVE-2008-3546 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in GIT
Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute arbitrary code via a PATH whose length is larger than the system's PATH_MAX when running GIT utilities such as git-diff or git-grep.
network
low complexity
linux git CWE-119
7.5
2008-08-06 CVE-2008-3496 Classic Buffer Overflow vulnerability in Linux Kernel
Buffer overflow in format descriptor parsing in the uvc_parse_format function in drivers/media/video/uvc/uvc_driver.c in uvcvideo in the video4linux (V4L) implementation in the Linux kernel before 2.6.26.1 has unknown impact and attack vectors.
network
low complexity
linux CWE-120
critical
10.0
2008-08-05 CVE-2008-3389 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Ingres 2.6/2006
Stack-based buffer overflow in the libbecompat library in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges by setting a long value of an environment variable before running (1) verifydb, (2) iimerge, or (3) csreport.
local
low complexity
hp linux ingres CWE-119
4.6
2008-08-05 CVE-2008-3357 Permissions, Privileges, and Access Controls vulnerability in multiple products
Untrusted search path vulnerability in ingvalidpw in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges via a crafted shared library, related to a "pointer overwrite vulnerability." Fixes are available for the current release of Ingres 2006 release 2 (9.1.0), for Ingres 2006 release 1 (9.0.4), and for Ingres 2.6 versions on their respective platforms.
local
low complexity
ingres hp linux CWE-264
7.2
2008-08-01 CVE-2008-1810 Permissions, Privileges, and Access Controls vulnerability in SAP Maxdb 7.6.03.15
Untrusted search path vulnerability in dbmsrv in SAP MaxDB 7.6.03.15 on Linux allows local users to gain privileges via a modified PATH environment variable.
local
linux sap CWE-264
4.4