SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-0495

Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.

HIGH 7.2EPSS 0.42%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.

CVSS 2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
0.42% probability · 36th percentile
CISA KEV
Not listed
Affected
avaya/converged communications server · avaya/modular messaging message storage server · gentoo/linux · linux/linux kernel · redhat/enterprise linux · suse/suse linux · avaya/intuity audix · suse/suse email server · suse/suse linux admin-cd for firewall · suse/suse linux connectivity server · suse/suse linux database server · suse/suse linux firewall cd · suse/suse linux office server · suse/suse office server · avaya/s8300 · avaya/s8500 · avaya/s8700 · conectiva/linux
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.