Search Results (Refine Search)
- CPE Product Version: cpe:/o:linux:linux_kernel:2.6.39:rc4
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2014-9803 |
arch/arm64/include/asm/pgtable.h in the Linux kernel before 3.15-rc5-next-20140519, as used in Android before 2016-07-05 on Nexus 5X and 6P devices, mishandles execute-only pages, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28557020. Published: July 10, 2016; 9:59:24 PM -0400 |
V3.0: 7.8 HIGH V2.0: 9.3 HIGH |
CVE-2011-2495 |
fs/proc/base.c in the Linux kernel before 2.6.39.4 does not properly restrict access to /proc/#####/io files, which allows local users to obtain sensitive I/O statistics by polling a file, as demonstrated by discovering the length of another user's password. Published: June 13, 2012; 6:24:55 AM -0400 |
V3.x:(not available) V2.0: 2.1 LOW |
CVE-2011-2211 |
The osf_wait4 function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform uses an incorrect pointer, which allows local users to gain privileges by writing a certain integer value to kernel memory. Published: June 13, 2012; 6:24:54 AM -0400 |
V3.x:(not available) V2.0: 7.2 HIGH |
CVE-2011-2210 |
The osf_getsysinfo function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform does not properly restrict the data size for GSI_GET_HWRPB operations, which allows local users to obtain sensitive information from kernel memory via a crafted call. Published: June 13, 2012; 6:24:54 AM -0400 |
V3.x:(not available) V2.0: 2.1 LOW |
CVE-2011-2209 |
Integer signedness error in the osf_sysinfo function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform allows local users to obtain sensitive information from kernel memory via a crafted call. Published: June 13, 2012; 6:24:54 AM -0400 |
V3.x:(not available) V2.0: 2.1 LOW |
CVE-2011-2208 |
Integer signedness error in the osf_getdomainname function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform allows local users to obtain sensitive information from kernel memory via a crafted call. Published: June 13, 2012; 6:24:54 AM -0400 |
V3.x:(not available) V2.0: 2.1 LOW |
CVE-2011-2183 |
Race condition in the scan_get_next_rmap_item function in mm/ksm.c in the Linux kernel before 2.6.39.3, when Kernel SamePage Merging (KSM) is enabled, allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted application. Published: June 13, 2012; 6:24:54 AM -0400 |
V3.x:(not available) V2.0: 4.0 MEDIUM |
CVE-2011-2182 |
The ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel before 2.6.39.1 does not properly handle memory allocation for non-initial fragments, which might allow local users to conduct buffer overflow attacks, and gain privileges or obtain sensitive information, via a crafted LDM partition table. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1017. Published: June 13, 2012; 6:24:54 AM -0400 |
V3.x:(not available) V2.0: 7.2 HIGH |
CVE-2011-1748 |
The raw_release function in net/can/raw.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation. Published: May 09, 2011; 6:55:03 PM -0400 |
V3.x:(not available) V2.0: 4.9 MEDIUM |
CVE-2011-1598 |
The bcm_release function in net/can/bcm.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation. Published: May 09, 2011; 6:55:03 PM -0400 |
V3.x:(not available) V2.0: 4.9 MEDIUM |