CVE-2010-0291
- EPSS 0.09%
- Published 15.02.2010 18:30:00
- Last modified 11.04.2025 00:51:21
The Linux kernel before 2.6.32.4 allows local users to gain privileges or cause a denial of service (panic) by calling the (1) mmap or (2) mremap function, aka the "do_mremap() mess" or "mremap/mmap mess."
CVE-2010-0622
- EPSS 0.09%
- Published 15.02.2010 18:30:00
- Last modified 11.04.2025 00:51:21
The wake_futex_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly handle certain unlock operations for a Priority Inheritance (PI) futex, which allows local users to cause a denial of service (OOPS) and possibly hav...
CVE-2010-0623
- EPSS 0.05%
- Published 15.02.2010 18:30:00
- Last modified 11.04.2025 00:51:21
The futex_lock_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly manage a certain reference count, which allows local users to cause a denial of service (OOPS) via vectors involving an unmount of an ext3 filesystem...
CVE-2010-0298
- EPSS 0.61%
- Published 12.02.2010 19:30:00
- Last modified 11.04.2025 00:51:21
The x86 emulator in KVM 83 does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) in determining the memory access available to CPL3 code, which allows guest OS users to cause a denial of service (guest OS crash) or gain privil...
CVE-2009-3556
- EPSS 0.03%
- Published 27.01.2010 17:30:00
- Last modified 11.04.2025 00:51:21
A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport...
CVE-2009-4272
- EPSS 1.81%
- Published 27.01.2010 17:30:00
- Last modified 11.04.2025 00:51:21
A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to cause a denial of service (deadlock) via crafted packets that force collisions in the IPv4 routing hash table, and...
CVE-2010-0003
- EPSS 0.06%
- Published 26.01.2010 18:30:01
- Last modified 11.04.2025 00:51:21
The print_fatal_signal function in kernel/signal.c in the Linux kernel before 2.6.32.4 on the i386 platform, when print-fatal-signals is enabled, allows local users to discover the contents of arbitrary memory locations by jumping to an address and t...
CVE-2010-0006
- EPSS 2.18%
- Published 26.01.2010 18:30:01
- Last modified 11.04.2025 00:51:21
The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.32.4, when network namespaces are enabled, allows remote attackers to cause a denial of service (NULL pointer dereference) via an invalid IPv6 jumbogram, a related issue...
CVE-2010-0007
- EPSS 0.07%
- Published 19.01.2010 16:30:01
- Last modified 11.04.2025 00:51:21
net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access r...
CVE-2009-4141
- EPSS 0.12%
- Published 19.01.2010 16:30:00
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privileges via vectors that include enabling O_ASYNC (aka FASYNC or FIOASYNC) on a locked file, and then cl...