4.6

CVE-2009-2793

The kernel in NetBSD, probably 5.0.1 and earlier, on x86 platforms does not properly handle a pre-commit failure of the iret instruction, which might allow local users to gain privileges via vectors related to a tempEIP pseudocode variable that is outside of the code-segment limits.

Data is provided by the National Vulnerability Database (NVD)
NetbsdNetbsd Version <= 5.0.1
NetbsdNetbsd Version0.8
NetbsdNetbsd Version0.9
NetbsdNetbsd Version1.0
NetbsdNetbsd Version1.1
NetbsdNetbsd Version1.2
NetbsdNetbsd Version1.2.1
NetbsdNetbsd Version1.3
NetbsdNetbsd Version1.3.1
NetbsdNetbsd Version1.3.2
NetbsdNetbsd Version1.3.3
NetbsdNetbsd Version1.5
NetbsdNetbsd Version1.5.1
NetbsdNetbsd Version1.5.2
NetbsdNetbsd Version1.5.3
NetbsdNetbsd Version1.6
NetbsdNetbsd Version1.6.1
NetbsdNetbsd Version1.6.2
NetbsdNetbsd Version2.0
NetbsdNetbsd Version2.0.1
NetbsdNetbsd Version2.0.2
NetbsdNetbsd Version2.0.3
NetbsdNetbsd Version2.1
NetbsdNetbsd Version3.0
NetbsdNetbsd Version3.0.1
NetbsdNetbsd Version3.0.2
NetbsdNetbsd Version3.1
NetbsdNetbsd Version4.0
NetbsdNetbsd Version4.0.1
NetbsdNetbsd Version5.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.195
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P