This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
| Summuary | |
|---|---|
| CPE Name | cpe:/o:linux:linux_kernel:2.6.24:rc3 |
| Detail | |||
|---|---|---|---|
| Vendor | Linux | First view | 2007-12-03 |
| Product | Linux Kernel | Last view | 2013-03-01 |
| Version | 2.6.24 | Type | Os |
| Edition | |||
| Language | |||
| Update | rc3 | ||
| CPE Product | cpe:/o:linux:linux_kernel | ||
Activity : Yearly
Related : CVE
This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 4 | 2013-03-01 | CVE-2011-3638 | Local | High | None Requ... | |
| 4.9 | 2013-03-01 | CVE-2011-2491 | Local | Low | None Requ... | |
| 4.9 | 2013-03-01 | CVE-2011-2479 | Local | Low | None Requ... | |
| 3.6 | 2013-03-01 | CVE-2011-1182 | Local | Low | None Requ... | |
| 1.9 | 2013-03-01 | CVE-2011-1019 | Local | Medium | None Requ... | |
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 5.4 | 2012-10-03 | CVE-2012-3552 | Network | High | None Requ... | |
| 4 | 2012-05-24 | CVE-2011-4080 | Local | High | None Requ... | |
| 5.4 | 2012-05-24 | CVE-2011-3363 | Network | High | None Requ... | |
| 5.4 | 2012-05-24 | CVE-2011-3359 | Network | High | None Requ... | |
| 4.9 | 2012-05-24 | CVE-2011-2521 | Local | Low | None Requ... | |
| 4.9 | 2012-05-24 | CVE-2011-2518 | Local | Low | None Requ... | |
| 7.2 | 2012-05-24 | CVE-2011-2517 | Local | Low | None Requ... | |
| 4.9 | 2012-05-17 | CVE-2012-0879 | Local | Low | None Requ... | |
| 4.9 | 2012-05-17 | CVE-2011-4621 | Local | Low | None Requ... | |
| 4.9 | 2012-05-17 | CVE-2011-4611 | Local | Low | None Requ... | |
| 7.1 | 2012-05-17 | CVE-2011-4326 | Network | Medium | None Requ... | |
| 4.9 | 2012-05-17 | CVE-2011-3637 | Local | Low | None Requ... | |
| 7.2 | 2012-02-01 | CVE-2011-2525 | Local | Low | None Requ... | |
| 5 | 2012-02-01 | CVE-2011-1573 | Network | Low | None Requ... | |
| 5.7 | 2011-10-23 | CVE-2011-1478 | Adjacent ... | Medium | None Requ... | |
| 7.8 | 2011-10-10 | CVE-2011-2189 | Network | Low | None Requ... | |
| 7.8 | 2011-10-04 | CVE-2011-1076 | Network | Low | None Requ... | |
| 5.7 | 2011-09-06 | CVE-2011-2723 | Adjacent ... | Medium | None Requ... | |
| 2.1 | 2011-09-06 | CVE-2011-2700 | Local | Low | None Requ... |
CWE : Common Weakness Enumeration
| % | id | Name |
|---|---|---|
| 19% (43) | CWE-399 | Resource Management Errors |
| 16% (36) | CWE-189 | Numeric Errors |
| 15% (35) | CWE-200 | Information Exposure |
| 15% (35) | CWE-20 | Improper Input Validation |
| 12% (28) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
| % | id | Name |
|---|---|---|
| 9% (21) | CWE-264 | Permissions, Privileges, and Access Controls |
| 5% (12) | CWE-362 | Race Condition |
| 2% (6) | CWE-16 | Configuration |
| 0% (2) | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
| 0% (1) | CWE-310 | Cryptographic Issues |
CAPEC : Common Attack Pattern Enumeration & Classificatio
This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
| id | Name |
|---|---|
| CAPEC-3 | Using Leading 'Ghost' Character Sequences to Bypass Input Filters |
| CAPEC-7 | Blind SQL Injection |
| CAPEC-8 | Buffer Overflow in an API Call |
| CAPEC-9 | Buffer Overflow in Local Command-Line Utilities |
| CAPEC-10 | Buffer Overflow via Environment Variables |
| id | Name |
|---|---|
| CAPEC-13 | Subverting Environment Variable Values |
| CAPEC-14 | Client-side Injection-induced Buffer Overflow |
| CAPEC-18 | Embedding Scripts in Nonscript Elements |
| CAPEC-22 | Exploiting Trust in Client (aka Make the Client Invisible) |
| CAPEC-24 | Filter Failure through Buffer Overflow |
| CAPEC-28 | Fuzzing |
| CAPEC-31 | Accessing/Intercepting/Modifying HTTP Cookies |
| CAPEC-32 | Embedding Scripts in HTTP Query Strings |
| CAPEC-42 | MIME Conversion |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
| CAPEC-45 | Buffer Overflow via Symbolic Links |
| CAPEC-46 | Overflow Variables and Tags |
| CAPEC-47 | Buffer Overflow via Parameter Expansion |
| CAPEC-52 | Embedding NULL Bytes |
| CAPEC-53 | Postfix, Null Terminate, and Backslash |
| CAPEC-63 | Simple Script Injection |
| CAPEC-64 | Using Slashes and URL Encoding Combined to Bypass Validation Logic |
| CAPEC-66 | SQL Injection |
| CAPEC-67 | String Format Overflow in syslog() |
| CAPEC-71 | Using Unicode Encoding to Bypass Validation Logic |
Oval Markup Language : Definitions
This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
| OvalID | Name |
|---|---|
| oval:org.mitre.oval:def:10719 | The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2... |
| oval:org.mitre.oval:def:10053 | fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does no... |
| oval:org.mitre.oval:def:11358 | The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does no... |
| oval:org.mitre.oval:def:11843 | Race condition in the directory notification subsystem (dnotify) in Linux ker... |
| oval:org.mitre.oval:def:9555 | arch/s390/kernel/ptrace.c in Linux kernel 2.6.9, and other versions before 2.... |
| id | Name |
|---|---|
| oval:org.mitre.oval:def:10065 | Linux kernel before 2.6.25.2 does not apply a certain protection mechanism fo... |
| oval:org.mitre.oval:def:10749 | Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 thr... |
| oval:org.mitre.oval:def:6633 | Linux Kernel TTY Operations NULL Pointer Dereference Denial of Service Vulner... |
| oval:org.mitre.oval:def:11632 | The Linux kernel before 2.6.25.10 does not properly perform tty operations, w... |
| oval:org.mitre.oval:def:11182 | The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.... |
| oval:org.mitre.oval:def:6551 | Linux Kernel UBIFS Orphan Inode Local Denial of Service Vulnerability |
| oval:org.mitre.oval:def:10744 | The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs ... |
| oval:org.mitre.oval:def:6340 | TCP/IP Zero Window Size Vulnerability |
| oval:org.mitre.oval:def:10584 | The inotify functionality in Linux kernel 2.6 before 2.6.28-rc5 might allow l... |
| oval:org.mitre.oval:def:9385 | The __qdisc_run function in net/sched/sch_generic.c in the Linux kernel befor... |
| oval:org.mitre.oval:def:7947 | VMware kernel clone system call vulnerability |
| oval:org.mitre.oval:def:11187 | The clone system call in the Linux kernel 2.6.28 and earlier allows local use... |
| oval:org.mitre.oval:def:7734 | VMware kernel drivers/firmware/dell_rbu.c vulnerability |
| oval:org.mitre.oval:def:10163 | drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.... |
| oval:org.mitre.oval:def:8685 | VMware kernel skfp_ioctl function vulnerability |
| oval:org.mitre.oval:def:11529 | The skfp_ioctl function in drivers/net/skfp/skfddi.c in the Linux kernel befo... |
| oval:org.mitre.oval:def:8618 | VMware kernel sock_getsockopt function vulnerability |
| oval:org.mitre.oval:def:11653 | The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.... |
| oval:org.mitre.oval:def:7867 | VMware kernel icmp_send function vulnerability |
| oval:org.mitre.oval:def:10215 | The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, ... |
Open Source Vulnerability Database (OSVDB)
This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
| id | Description |
|---|---|
| 78302 | Linux Kernel m_stop() Implementation Local DoS |
| 77295 | Linux Kernel UFO IPv6 UDP Datagram Parsing Remote DoS |
| 77293 | Linux Kernel b43 Driver Wireless Interface Frame Parsing Remote DoS |
| 76805 | Linux Kernel net/core/net_namespace.c Network Namespace Cleanup Weakness Remo... |
| 76666 | Linux Kernel ext4 Extent Splitting BUG_ON() Local DoS |
| id | Description |
|---|---|
| 76177 | Linux Kernel Performance Events NMI Watchdog Local DoS |
| 75580 | Linux Kernel CIFS Share Mounting DIFS Referral BUG_ON() Remote DoS |
| 74881 | Linux Kernel si4713-i2c si4713_write_econtrol_string Function Radio Driver Lo... |
| 74823 | Linux Kernel fs/befs/linuxvfs.c befs_follow_link Function Be Filesystem Symli... |
| 74679 | Linux Kernel Bluetooth net/bluetooth/l2cap_core.c l2cap_config_req Function O... |
| 74660 | Linux Kernel NFS Server File Locking Local DoS |
| 74658 | Linux Kernel trigger_scan / sched_scan SSID Length Handling Bypass |
| 74657 | Linux Kernel Packet Scheduler API Implementation tc_fill_qdisc() Function NUL... |
| 74654 | Linux Kernel EFI GUID Partition Table (GPT) Implementation Crafted Partition ... |
| 74653 | Linux Kernel net/ipv4/inet_diag.c inet_diag_bc_audit() Function Local DoS |
| 74645 | Linux Kernel Common Internet File System (CIFS) Implementation cifs_close() F... |
| 74643 | Linux Kernel dev_load() Function CAP_NET_ADMIN Capability Arbitrary Module Lo... |
| 74635 | Linux Kernel AARESOLVE_OFFSET Memory Overwrite Local Privilege Escalation |
| 74138 | Linux Kernel GRO include/linux/netdevice.h skb_gro_header_slow() Function Rem... |
| 74123 | Linux Kernel ext4 Subsystem Extent Format Sparse File Off-by-one Local DoS |
| 73882 | Linux Kernel DCCP net/dccp/input.c dccp_rcv_state_process Function CLOSED End... |
| 73872 | Linux Kernel fs/proc/array.c do_task_stat Function Local ASLR Protection Mech... |
| 73802 | Linux Kernel fs/gfs2/file.c GFS2 gfs2_fallocate() Function Local DoS |
| 73460 | Linux Kernel Bluetooth net/bluetooth/rfcomm/sock.c rfcomm_sock_getsockopt_old... |
| 73459 | Linux Kernel Bluetooth net/bluetooth/l2cap_sock.c l2cap_sock_getsockopt_old()... |
Milw0rm Exploits
| id | Description |
|---|---|
| 2008-02-09 | Linux Kernel 2.6.23 - 2.6.24 vmsplice Local Root Exploit |
| 2008-02-09 | Linux Kernel 2.6.17 - 2.6.24.1 vmsplice Local Root Exploit |
ExploitDB Exploits
| id | Description |
|---|---|
| 17787 | Linux Kernel < 2.6.36.2 Econet Privilege Escalation Exploit |
| 16973 | Linux <= 2.6.37-rc1 serial_core TIOCGICOUNT Leak Exploit |
| 16952 | Linux Kernel < 2.6.37-rc2 TCP_MAXSEG Kernel Panic DoS |
| 16263 | Linux Kernel <= 2.6.37 Local Kernel Denial of Service |
| 15774 | Linux Kernel < 2.6.37-rc2 ACPI custom_method Privilege Escalation |
| id | Description |
|---|---|
| 15704 | Linux Kernel <= 2.6.37 Local Privilege Escalation |
| 15344 | Linux Kernel VIDIOCSMICROCODE IOCTL Local Memory Overwrite Vulnerability |
| 15285 | Linux RDS Protocol Local Privilege Escalation |
| 15150 | Linux Kernel < 2.6.36-rc6 pktcdvd Kernel Memory Disclosure |
| 14814 | Linux Kernel < 2.6.36-rc1 CAN BCM Privilege Escalation Exploit |
| 14594 | Linux Kernel <= 2.6.33.3 SCTP INIT Remote DoS |












