CVE-2010-2240
- EPSS 0.1%
- Veröffentlicht 03.09.2010 20:00:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The do_anonymous_page function in mm/memory.c in the Linux kernel before 2.6.27.52, 2.6.32.x before 2.6.32.19, 2.6.34.x before 2.6.34.4, and 2.6.35.x before 2.6.35.2 does not properly separate the stack and the heap, which allows context-dependent at...
CVE-2010-3015
- EPSS 0.15%
- Veröffentlicht 20.08.2010 18:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the ext4_ext_get_blocks function in fs/ext4/extents.c in the Linux kernel before 2.6.34 allows local users to cause a denial of service (BUG and system crash) via a write operation on the last block of a large file, followed by a ...
CVE-2010-2071
- EPSS 0.06%
- Veröffentlicht 16.06.2010 20:30:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The btrfs_xattr_set_acl function in fs/btrfs/acl.c in btrfs in the Linux kernel 2.6.34 and earlier does not check file ownership before setting an ACL, which allows local users to bypass file permissions by setting arbitrary ACLs, as demonstrated usi...
CVE-2010-1636
- EPSS 0.24%
- Veröffentlicht 08.06.2010 00:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the btrfs functionality in the Linux kernel 2.6.29 through 2.6.32, and possibly other versions, does not ensure that a cloned file descriptor has been opened for reading, which allows local users ...
CVE-2008-7256
- EPSS 0.11%
- Veröffentlicht 03.06.2010 14:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
mm/shmem.c in the Linux kernel before 2.6.28-rc8, when strict overcommit is enabled and CONFIG_SECURITY is disabled, does not properly handle the export of shmemfs objects by knfsd, which allows attackers to cause a denial of service (NULL pointer de...
CVE-2010-1643
- EPSS 0.09%
- Veröffentlicht 03.06.2010 14:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
mm/shmem.c in the Linux kernel before 2.6.28-rc3, when strict overcommit is enabled, does not properly handle the export of shmemfs objects by knfsd, which allows attackers to cause a denial of service (NULL pointer dereference and knfsd crash) or po...
CVE-2010-1641
- EPSS 0.07%
- Veröffentlicht 01.06.2010 20:30:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel before 2.6.34-git10 does not verify the ownership of a file, which allows local users to bypass intended access restrictions via a SETFLAGS ioctl request.
CVE-2010-1436
- EPSS 0.07%
- Veröffentlicht 21.05.2010 17:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
gfs2 in the Linux kernel 2.6.18, and possibly other versions, does not properly handle when the gfs2_quota struct occupies two separate pages, which allows local users to cause a denial of service (kernel panic) via certain manipulations that cause a...
CVE-2010-1446
- EPSS 0.06%
- Veröffentlicht 21.05.2010 17:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
arch/powerpc/mm/fsl_booke_mmu.c in KGDB in the Linux kernel 2.6.30 and other versions before 2.6.33, when running on PowerPC, does not properly perform a security check for access to a kernel page, which allows local users to overwrite arbitrary kern...
CVE-2010-1173
- EPSS 11.43%
- Veröffentlicht 07.05.2010 18:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The sctp_process_unk_param function in net/sctp/sm_make_chunk.c in the Linux kernel 2.6.33.3 and earlier, when SCTP is enabled, allows remote attackers to cause a denial of service (system crash) via an SCTPChunkInit packet containing multiple invali...