← Vulnerability feed

Vulnerability record · CVE-2004-0554 · published 6 August 2004

CVE-2004-0554: Avaya converged communications server vulnerability

Avaya · Converged Communications Server

Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.

2.1 CVSS 2.0 Low EPSS 0.87% · top 42.9%
2.1CVSS 2.0 base score
0.87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
18Affected product versions listed by NVD
52References
16 Jun 2026Last modified by NVD

Description

Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.

AV:L/AC:L/Au:N/C:N/I:N/A:P

Affected products

18 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000845
http://gcc.gnu.org/bugzilla/show_bug.cgi?id=15905
http://linuxreviews.org/news/2004-06-11_kernel_crash/index.html
http://lwn.net/Articles/91155/
http://marc.info/?l=bugtraq&m=108786114032681&w=2
http://marc.info/?l=bugtraq&m=108793699910896&w=2
http://marc.info/?l=linux-kernel&m=108681568931323&w=2
http://secunia.com/advisories/20162
http://secunia.com/advisories/20163
http://secunia.com/advisories/20202
http://secunia.com/advisories/20338
http://security.gentoo.org/glsa/glsa-200407-02.xml
http://www.debian.org/security/2006/dsa-1067
http://www.debian.org/security/2006/dsa-1069
http://www.debian.org/security/2006/dsa-1070
http://www.debian.org/security/2006/dsa-1082
http://www.kb.cert.org/vuls/id/973654 Third Party AdvisoryUS Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2004:062
http://www.novell.com/linux/security/advisories/2004_17_kernel.html
http://www.redhat.com/support/errata/RHSA-2004-255.html
http://www.redhat.com/support/errata/RHSA-2004-260.html
http://www.securityfocus.com/bid/10538
http://www.trustix.net/errata/2004/0034/
https://exchange.xforce.ibmcloud.com/vulnerabilities/16412
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2915
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9426
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000845
http://gcc.gnu.org/bugzilla/show_bug.cgi?id=15905
http://linuxreviews.org/news/2004-06-11_kernel_crash/index.html
http://lwn.net/Articles/91155/
http://marc.info/?l=bugtraq&m=108786114032681&w=2
http://marc.info/?l=bugtraq&m=108793699910896&w=2
http://marc.info/?l=linux-kernel&m=108681568931323&w=2
http://secunia.com/advisories/20162
http://secunia.com/advisories/20163
http://secunia.com/advisories/20202
http://secunia.com/advisories/20338
http://security.gentoo.org/glsa/glsa-200407-02.xml
http://www.debian.org/security/2006/dsa-1067
http://www.debian.org/security/2006/dsa-1069

Track CVE-2004-0554 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-1050Internet Explorer 6 heap overflow via IFRAME, FRAME and EMBED attributesInternet Explorer 6 contains a heap-based buffer overflow triggered by long SRC or NAME attributes in IFRAME, FRAME and EMBED elements. A remote atta…EPSS 67%analysed10.0CVE-2004-0201Microsoft HTML Help hh.exe heap buffer overflow via crafted CHM fileThe HTML Help program (hh.exe) in multiple Microsoft Windows versions contains a heap-based buffer overflow triggered by a .CHM file with a large len…EPSS 45%analysed10.0CVE-2004-0212Windows Task Scheduler .job file stack buffer overflowThe Windows Task Scheduler in Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, contains a stack-based buffer overflow triggered by a .…EPSS 64%analysed7.5CVE-2004-0842Internet Explorer CSS heap memory corruption denial of serviceInternet Explorer 6.0 SP1 and earlier mishandles malformed Cascading Style Sheet elements, triggering a heap-based buffer overflow that crashes the a…EPSS 57%analysed7.5CVE-2004-1307Avaya call management system server vulnerabilityInteger overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF …EPSS 6.3%7.5CVE-2004-0079Cisco firewall services module null pointer dereference vulnerabilityThe do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) vi…EPSS 9.5%7.5CVE-2004-1082Apache http server vulnerabilitymod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attacke…EPSS 7.6%7.2CVE-2004-0495Avaya converged communications server vulnerabilityMultiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse sou…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2004-0554), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.