CVE-2004-2686
HIGH 7.2EPSS 1.2%
Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure.
- CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 1.17% chance of exploitation in the next 30 days, 65th percentile
- Published
- 2007-09-23
- Updated
- 2024-08-08
Proof-of-concept exploits (2)
- http://seclists.org/bugtraq/2004/Apr/0081.html
- http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2004-04/0297.html