cbcvebase.
CVE-2004-1235
published 2005-04-14

CVE-2004-1235: Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows…

PriorityP427medium6.2CVSS 2.0
AVLACHAuNCCICAC
EXPLOIT
EPSS
2.89%
85.4th percentile
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.

Affected

79 ranges· showing 25
VendorProductVersion rangeFixed in
avayaconverged_communications_server
avayamodular_messaging_message_storage_server
avayamodular_messaging_message_storage_server
avayas8300
avayas8300
avayas8500
avayas8500
avayas8700
avayas8700
avayas8710
avayas8710
conectivalinux
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel

CVSS provenance

nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
vendor_redhat6.2MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.