| OSVDB ID | Disclosure Date | Title |
|
20426
Description:
Unknown / Incomplete
|
2005-10-12
|
Linux Kernel Yealink Driver map_to_seg7() Function Local Overflow
|
|
58235
Description:
(Description Provided by CVE) : The z90crypt_unlocked_ioctl function in the z90crypt driver in the Linux kernel 2.6.9 does not perform a capability check for the Z90QUIESCE operation, which allows local users to leverage euid 0 privileges to force a driver outage.
|
2009-09-15
|
Linux Kernel z90crypt Driver z90crypt_unlocked_ioctl Function Z90QUIESCE Operation Local DoS
|
|
5941
Description:
Linux kernel contains a flaw that may allow a remote denial of service. The issue is triggered when a 0-length IP fragment is received, if it is the first fragment in the list. A remote attacker can send several thousands 0-length packets to the target and will result in loss of availability.
|
1999-03-24
|
Linux Kernel Zero Length IP Fragmentation DoS
|
|
19027
Description:
(Description Provided by CVE) : The driver for compressed ISO file systems (zisofs) in the Linux kernel before 2.6.12.5 allows local users and remote attackers to cause a denial of service (kernel crash) via a crafted compressed ISO file system.
|
2005-08-19
|
Linux Kernel zisofs Driver Crafted ISO File System DoS
|
|
19028
Description:
(Description Provided by CVE) : The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a certain compressed file that leads to a null pointer dereference, a different vulnerbility than CVE-2005-2458.
|
2005-07-25
|
Linux Kernel zlib inflate.c huft_build Function Null Pointer Dereference Local DoS
|
|
19026
Description:
(Description Provided by CVE) : inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 allows remote attackers to cause a denial of service (kernel crash) via a compressed file with "improper tables".
|
2005-07-25
|
Linux Kernel zlib inflate.c Improper Tables File Local DoS
|
|
30215
Description:
(Description Provided by CVE) : The zlib_inflate function in Linux kernel 2.6.x allows local users to cause a denial of service (crash) via a malformed filesystem that uses zlib compression that triggers memory corruption, as demonstrated using cramfs.
|
2006-11-07
|
Linux Kernel zlib_inflate() Function Crafted Filesystem Memory Corruption
|
|
42614
Description:
(Description Provided by CVE) : Format string vulnerability in the log_message function in lks.c in Linux Kiss Server 1.2, when background (daemon) mode is disabled, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in an invalid command.
|
2008-03-04
|
Linux Kiss Server lks.c log_message() Function Remote Format String
|
|
57715
Description:
(Description Provided by CVE) : String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges.
|
2000-08-10
|
Linux knfsd / linuxnfs rpc.kstatd Remote Format String
|
|
1259
Description:
(Description Provided by CVE) : Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges.
|
2000-03-16
|
Linux kreatecd Path Subversion Privilege Escalation
|
|
8219
Description:
A local overflow exists in the 'ld-linux.so' dynamic linkers in some Linux distributions. By forcing an error while calling a dynamically linked setuid program with a long program name (argv[0]), a local attacker can overflow a buffer and execute arbitrary code on the system gaining root privileges.
|
1997-07-17
|
Linux ld-linux.so Program Name Overflow
|
|
8218
Description:
A local overflow exists in the 'ld.so' dynamic linkers in some Linux distributions. By forcing an error while calling a dynamically linked setuid program with a long program name (argv[0]), a local attacker can overflow a buffer and execute arbitrary code on the system and use this vulnerability to gain root privileges on the system.
|
1997-07-17
|
Linux ld.so Program Name Overflow
|
|
61460
Description:
Linux is prone to an overflow condition. libc fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted NLSPATH variable, a local attacker can potentially cause arbitrary code execution.
|
1996-02-13
|
Linux libc NLSPATH Environment Variable Local Overflow
|
|
30355
Description:
(Description Provided by CVE) : Untrusted search path vulnerability in libgpib-perl 3.2.06-2 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the LinuxGpib.so module, which might allow local users to gain privileges by installing malicious libraries in that directory.
|
2006-03-27
|
Linux libgpib-perl Path Subversion Local Privilege Escalation
|
|
30356
Description:
(Description Provided by CVE) : Untrusted search path vulnerability in libtunepimp-perl 0.4.2-1 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the tunepimp.so module, which might allow local users to gain privileges by installing malicious libraries in that directory.
|
2006-03-27
|
Linux libtunepimp-perl Search Path Subversion Local Privilege Escalation
|
|
1756
Description:
(Description Provided by CVE) : Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.
|
2001-01-31
|
Linux man -l Format String
|
|
1233
Description:
(Description Provided by CVE) : Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable.
|
2000-02-26
|
Linux man MANPAGER Variable Local Overflow
|
|
13502
Description:
(Description Provided by CVE) : mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges.
|
1999-09-28
|
Linux mknod Symlink Privilege Escalation
|
|
1641
Description:
(Description Provided by CVE) : modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.
|
2000-11-12
|
Linux modprobe popen Function Arbitrary Command Execution
|
|
6980
Description:
A local overflow exists in some Linux distributions. The mount command fails to validate arguments resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2000-02-03
|
Linux mount Long Relative Path Overflow
|
|
333
Description:
Unknown / Incomplete
|
1995-07-12
|
Linux Multiple ftpd /proc File Descriptor Arbitrary File Access
|
|
30339
Description:
(Description Provided by CVE) : ftpd in linux-ftpd 0.17, and possibly other versions, performs a chdir before setting the UID, which allows local users to bypass intended access restrictions by redirecting their home directory to a restricted directory.
|
2006-08-24
|
Linux NetKit FTP Server (linux-ftpd) NFS Home Directory Symlink Privilege Escalation
|
|
30340
Description:
(Description Provided by CVE) : ftpd in Linux Netkit (linux-ftpd) 0.17, and possibly other versions, does not check the return status of certain seteuid, setgid, and setuid calls, which might allow remote authenticated users to gain privileges if these calls fail in cases such as PAM failures or resource limits, a different vulnerability than CVE-2006-5778.
|
2006-08-24
|
Linux NetKit FTP Server ID Calls Return Unspecified Privilege Escalation
|
|
30923
Description:
(Description Provided by CVE) : The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (process crash) and deny access to NFS exports via unspecified vectors that trigger a kernel oops (null dereference) and a deadlock.
|
2005-12-16
|
Linux NFS lockd nlmclnt_mark_reclaim Function DoS
|
|
11279
Description:
A remote overflow exists in NFS Server. The application fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted request containing an overly long pathname on a read-write mounted NFS directory, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
1999-11-09
|
Linux NFS Server Pathname Overflow
|
|
2317
Description:
nfs-utils contains a flaw that allows a remote attacker to gain root privileges. The issue is due to a buffer overflow caused by an off-by-one error in the "xlog" function. If an attacker creates a specially crafted RPC request to the rpc.mountd daemon they may be able to execute arbitrary code.
|
2003-07-14
|
Linux NFS utils package (nfs-utils) mountd xlog Function Off-by-one Remote Overflow
|
|
22756
Description:
(Description Provided by CVE) : Buffer overflow in the realpath function in nfs-server rpc.mountd, as used in SUSE Linux 9.1 through 10.0, allows local users to execute arbitrary code via unspecified vectors involving mount requests and symlinks.
|
2006-01-26
|
Linux nfs-server rpc.mountd realpath() Function Overflow
|
|
443
Description:
The rpc.statd program contained in the nfs-utils package contains a flaw that may allow a malicious user to gain remote root access. The issue is triggered when raw user input is passed to the syslog() function. It is possible that the flaw may allow arbitrary code exectuion resulting in a loss of integrity.
|
2000-07-16
|
Linux nfs-utils rpc.statd Remote Format String
|
|
11514
Description:
(Description Provided by CVE) : Some configurations of NIS+ in Linux allowed attackers to log in as the user "+".
|
1995-09-05
|
Linux NIS+ Plus Character Remote Login
|
|
30508
Description:
(Description Provided by CVE) : The NTFS filesystem code in Linux kernel 2.6.x up to 2.6.18, and possibly other versions, allows local users to cause a denial of service (CPU consumption) via a malformed NTFS file stream that triggers an infinite loop in the __find_get_block_slow function.
|
2006-11-19
|
Linux NTFS __find_get_block_slow() Function DoS
|