Vulnerabilities > Linux > High

DATE CVE VULNERABILITY TITLE RISK
2005-09-06 CVE-2005-2801 Incorrect Comparison vulnerability in Linux Kernel 2.6.0
xattr.c in the ext2 and ext3 file system code for Linux kernel 2.6 does not properly compare the name_index fields when sharing xattr blocks, which could prevent default ACLs from being applied.
network
low complexity
linux CWE-697
7.5
2005-05-17 CVE-2005-1589 Local Memory Corruption vulnerability in Multiple Linux Kernel IOCTL Handlers
The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space and allows local users to cause a denial of service and possibly execute arbitrary code, a similar vulnerability to CVE-2005-1264.
local
low complexity
linux
7.2
2005-05-17 CVE-2005-1264 Local Memory Corruption vulnerability in Multiple Linux Kernel IOCTL Handlers
Raw character devices (raw.c) in the Linux kernel 2.6.x call the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space, a similar vulnerability to CVE-2005-1589.
local
low complexity
linux
7.2
2005-05-11 CVE-2005-1263 Local Buffer Overflow vulnerability in Linux Kernel ELF Core Dump
The elf_core_dump function in binfmt_elf.c for Linux kernel 2.x.x to 2.2.27-rc2, 2.4.x to 2.4.31-pre1, and 2.6.x to 2.6.12-rc4 allows local users to execute arbitrary code via an ELF binary that, in certain conditions involving the create_elf_tables function, causes a negative length argument to pass a signed integer comparison, leading to a buffer overflow.
local
low complexity
linux
7.2
2005-05-02 CVE-2005-0867 Unspecified vulnerability in Linux Kernel 2.6.0
Integer overflow in Linux kernel 2.6 allows local users to overwrite kernel memory by writing to a sysfs file.
local
low complexity
linux
7.2
2005-05-02 CVE-2005-0449 Improper Input Validation vulnerability in Linux Kernel
The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are not properly handled by the skb_checksum_help function.
network
linux CWE-20
7.1
2005-05-02 CVE-2005-0209 Improper Input Validation vulnerability in Linux Kernel 2.6.8.1
Netfilter in Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via crafted IP packet fragments.
network
low complexity
linux CWE-20
7.8
2005-04-01 CVE-2005-0749 Local Denial of Service vulnerability in Linux Kernel Elf Binary Loading
The load_elf_library in the Linux kernel before 2.6.11.6 allows local users to cause a denial of service (kernel crash) via a crafted ELF library or executable, which causes a free of an invalid pointer.
local
low complexity
linux
7.2
2005-03-27 CVE-2005-0750 Buffer Index vulnerability in Linux Kernel Bluetooth Signed
The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.
local
low complexity
conectiva linux redhat suse ubuntu
7.2
2005-03-01 CVE-2004-0986 Iptables before 1.2.11, under certain conditions, does not properly load the required modules at system startup, which causes the firewall rules to fail to load and protect the system from remote attackers.
network
low complexity
suse debian linux redhat
7.5