Linux Kernel CVE

Known vulnerabilities for Linux Kernel — CVSS scores, severity ratings and security advisories.

14,893 CVEs indexed for Linux Kernel · Source: NIST NVD

CVE-1999-1387
MEDIUM
5.0Published 2 avr. 1997
See details

Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.

CVE-1999-1442
HIGH
7.2Published 22 juin 1998
See details

Bug in AMD K6 processor on Linux 2.0.x and 2.1.x kernels allows local users to cause a denial of service (crash) via a particular sequence of instructions, possibly related to accessing addresses outside of segments.

CVE-1999-1406
LOW
2.1Published 29 juil. 1998
See details

dumpreg in Red Hat Linux 5.1 opens /dev/mem with O_RDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel.

CVE-1999-0804
MEDIUM
5.0Published 1 juin 1999
See details

Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.

CVE-1999-1166
HIGH
7.2Published 11 juil. 1999
See details

Linux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by accessing and modifying kernel memory.

CVE-1999-1018
HIGH
7.5Published 27 juil. 1999
See details

IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets.

CVE-1999-1341
MEDIUM
4.6Published 22 oct. 1999
See details

Linux kernel before 2.3.18 or 2.2.13pre15, with SLIP and PPP options, allows local unprivileged users to forge IP packets via the TIOCSETD option on tty devices.

CVE-2000-0227
LOW
2.1Published 23 mars 2000
See details

The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max parameter, which allows local users to cause a denial of service by requesting a large number of sockets.

CVE-2000-0274
LOW
2.1Published 10 avr. 2000
See details

The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a long name.

CVE-2000-0344
MEDIUM
5.0Published 1 mai 2000
See details

The knfsd NFS server in Linux kernel 2.2.x allows remote attackers to cause a denial of service via a negative size value.

CVE-2000-0506
HIGH
10.0Published 9 juin 2000
See details

The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to prevent a setuid program from dropping privileges, aka the "Linux kernel setuid/setcap vulnerability."

CVE-2000-0747
HIGH
10.0Published 20 oct. 2000
See details

The logrotate script for OpenLDAP before 1.2.11 in Conectiva Linux sends an improper signal to the kernel log daemon (klogd) and kills it.

CVE-2000-0867
HIGH
7.2Published 14 nov. 2000
See details

Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.

CVE-2001-1273
LOW
2.1Published 12 févr. 2001
See details

The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt).

CVE-2001-1390
MEDIUM
6.2Published 17 avr. 2001
See details

Unknown vulnerability in binfmt_misc in the Linux kernel before 2.2.19, related to user pages.

CVE-2001-1391
MEDIUM
5.5Published 17 avr. 2001
See details

Off-by-one vulnerability in CPIA driver of Linux kernel before 2.2.19 allows users to modify kernel memory.

CVE-2001-1392
LOW
2.1Published 17 avr. 2001
See details

The Linux kernel before 2.2.19 does not have unregister calls for (1) CPUID and (2) MSR drivers, which could cause a DoS (crash) by unloading and reloading the drivers.

CVE-2001-1393
LOW
2.1Published 17 avr. 2001
See details

Unknown vulnerability in classifier code for Linux kernel before 2.2.19 could result in denial of service (hang).

CVE-2001-1394
LOW
2.1Published 17 avr. 2001
See details

Signedness error in (1) getsockopt and (2) setsockopt for Linux kernel before 2.2.19 allows local users to cause a denial of service.

CVE-2001-1395
LOW
3.6Published 17 avr. 2001
See details

Unknown vulnerability in sockfilter for Linux kernel before 2.2.19 related to "boundary cases," with unknown impact.