← Vulnerability feed

Vulnerability record · CVE-2005-0003 · published 14 April 2005

CVE-2005-0003: Avaya mn100 vulnerability

Avaya · Mn100

The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.

2.1 CVSS 2.0 Low EPSS 0.51% · top 58.3%
2.1CVSS 2.0 base score
0.51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
15Affected product versions listed by NVD
36References
16 Jun 2026Last modified by NVD

Description

The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.

AV:L/AC:L/Au:N/C:N/I:N/A:P

Affected products

15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://linux.bkbits.net:8080/linux-2.4/cset%4041c36fb6q1Z68WUzKQFjJR-40Ev3tw
http://linux.bkbits.net:8080/linux-2.6/cset%4041a6721cce-LoPqkzKXudYby_3TUmg
http://secunia.com/advisories/20163
http://secunia.com/advisories/20202
http://secunia.com/advisories/20338
http://securitytracker.com/id?1012885
http://www.debian.org/security/2006/dsa-1067
http://www.debian.org/security/2006/dsa-1069
http://www.debian.org/security/2006/dsa-1070
http://www.debian.org/security/2006/dsa-1082
http://www.mandriva.com/security/advisories?name=MDKSA-2005:022
http://www.novell.com/linux/security/advisories/2005_18_kernel.html
http://www.redhat.com/support/errata/RHSA-2005-017.html
http://www.redhat.com/support/errata/RHSA-2005-043.html PatchVendor Advisory
http://www.securityfocus.com/bid/12261 PatchVendor Advisory
http://www.trustix.org/errata/2005/0001/
https://exchange.xforce.ibmcloud.com/vulnerabilities/18886
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9512
http://linux.bkbits.net:8080/linux-2.4/cset%4041c36fb6q1Z68WUzKQFjJR-40Ev3tw
http://linux.bkbits.net:8080/linux-2.6/cset%4041a6721cce-LoPqkzKXudYby_3TUmg
http://secunia.com/advisories/20163
http://secunia.com/advisories/20202
http://secunia.com/advisories/20338
http://securitytracker.com/id?1012885
http://www.debian.org/security/2006/dsa-1067
http://www.debian.org/security/2006/dsa-1069
http://www.debian.org/security/2006/dsa-1070
http://www.debian.org/security/2006/dsa-1082
http://www.mandriva.com/security/advisories?name=MDKSA-2005:022
http://www.novell.com/linux/security/advisories/2005_18_kernel.html
http://www.redhat.com/support/errata/RHSA-2005-017.html
http://www.redhat.com/support/errata/RHSA-2005-043.html PatchVendor Advisory
http://www.securityfocus.com/bid/12261 PatchVendor Advisory
http://www.trustix.org/errata/2005/0001/
https://exchange.xforce.ibmcloud.com/vulnerabilities/18886
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9512

Track CVE-2005-0003 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-1050Internet Explorer 6 heap overflow via IFRAME, FRAME and EMBED attributesInternet Explorer 6 contains a heap-based buffer overflow triggered by long SRC or NAME attributes in IFRAME, FRAME and EMBED elements. A remote atta…EPSS 67%analysed10.0CVE-2004-0201Microsoft HTML Help hh.exe heap buffer overflow via crafted CHM fileThe HTML Help program (hh.exe) in multiple Microsoft Windows versions contains a heap-based buffer overflow triggered by a .CHM file with a large len…EPSS 45%analysed10.0CVE-2004-0212Windows Task Scheduler .job file stack buffer overflowThe Windows Task Scheduler in Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, contains a stack-based buffer overflow triggered by a .…EPSS 64%analysed7.5CVE-2004-0842Internet Explorer CSS heap memory corruption denial of serviceInternet Explorer 6.0 SP1 and earlier mishandles malformed Cascading Style Sheet elements, triggering a heap-based buffer overflow that crashes the a…EPSS 57%analysed7.5CVE-2004-1307Avaya call management system server vulnerabilityInteger overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF …EPSS 6.3%7.5CVE-2004-0079Cisco firewall services module null pointer dereference vulnerabilityThe do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) vi…EPSS 9.5%7.5CVE-2004-1082Apache http server vulnerabilitymod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attacke…EPSS 7.6%7.2CVE-2004-0495Avaya converged communications server vulnerabilityMultiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse sou…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2005-0003), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.