Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges.
6.9high severity
AV:L/AC:M/Au:N/C:C/I:C/A:C
10/03/2007
Products1
Om
Omnikey Cardman 4040
by Omnikey.aaitg
2 Versions
17 years ago
Operating Systems1
Li
Linux Kernel
by Linux
5648 Versions
14 days ago
Vulnerability Categories1
Improper Restriction of Operations within the Bounds of a Memory Buffer
http://www.vicarius.io
is owned and operated by Vicarius Ltd. (the “Company”). All information contained on the
Website is purely for informational, and educational purposes and should be independently
verified and confirmed. Vicarius does not accept any liability for any loss or damage
whatsoever caused in reliance upon such information or services. No statements or information
presented in any form by Vicarius is intended as fact, and you agree that you will not
consider the statements or information presented on the Website as fact or as a guarantee of
performance.
Related CVEs
Security Research Topics
By David Parkinson Frost
Mar 21, 2024
David Rambles on Copilot and GPU Spies
By The Meme Bot
Mar 14, 2024
By Shivam Bathla
Mar 10, 2024
Unveiling CVE-2024-21501: Pursuing the abyss - Understanding and exploiting sanitize-html vulnerability, patch, and the root-cause!
Versions below 2.12.1 of the package sanitize-html are vulnerable to path disclosure when used on the backend and with the style attribute allowed, allowing verifying files and folder existence on the system (including project dependencies). An attacker could leverage this vulnerability to gather details about the file system structure and dependencies to perform more targeted attacks against the server. This post details the process of diving into the source code to uncover the root-cause and reveal how insecure usage of the third-party package could lead to seemingly innocuous yet noxious bugs.