CVE-2009-1192
- EPSS 0.09%
- Published 24.04.2009 15:30:00
- Last modified 09.04.2025 00:30:58
The (1) agp_generic_alloc_page and (2) agp_generic_alloc_pages functions in drivers/char/agp/generic.c in the agp subsystem in the Linux kernel before 2.6.30-rc3 do not zero out pages that may later be available to a user-space process, which allows ...
CVE-2009-1336
- EPSS 0.06%
- Published 22.04.2009 15:30:00
- Last modified 09.04.2025 00:30:58
fs/nfs/client.c in the Linux kernel before 2.6.23 does not properly initialize a certain structure member that stores the maximum NFS filename length, which allows local users to cause a denial of service (OOPS) via a long filename, related to the en...
CVE-2009-1337
- EPSS 0.3%
- Published 22.04.2009 15:30:00
- Last modified 09.04.2025 00:30:58
The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies ...
CVE-2009-1338
- EPSS 0.08%
- Published 22.04.2009 15:30:00
- Last modified 09.04.2025 00:30:58
The kill_something_info function in kernel/signal.c in the Linux kernel before 2.6.28 does not consider PID namespaces when processing signals directed to PID -1, which allows local users to bypass the intended namespace isolation, and send arbitrary...
CVE-2009-1360
- EPSS 1.77%
- Published 22.04.2009 15:30:00
- Last modified 09.04.2025 00:30:58
The __inet6_check_established function in net/ipv6/inet6_hashtables.c in the Linux kernel before 2.6.29, when Network Namespace Support (aka NET_NS) is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system...
- EPSS 2.34%
- Published 08.04.2009 01:30:00
- Last modified 09.04.2025 00:30:58
Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 2.6.24.4, and other versions before 2.6.30-rc1, might allow remote attackers to obtain sensitive information via a large length value, which causes "garbage" memory to be sent.
CVE-2009-1242
- EPSS 0.07%
- Published 06.04.2009 14:30:00
- Last modified 09.04.2025 00:30:58
The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode e...
CVE-2009-1243
- EPSS 0.07%
- Published 06.04.2009 14:30:00
- Last modified 09.04.2025 00:30:58
net/ipv4/udp.c in the Linux kernel before 2.6.29.1 performs an unlocking step in certain incorrect circumstances, which allows local users to cause a denial of service (panic) by reading zero bytes from the /proc/net/udp file and unspecified other fi...
CVE-2009-0787
- EPSS 0.08%
- Published 25.03.2009 01:30:00
- Last modified 09.04.2025 00:30:58
The ecryptfs_write_metadata_to_contents function in the eCryptfs functionality in the Linux kernel 2.6.28 before 2.6.28.9 uses an incorrect size when writing kernel memory to an eCryptfs file header, which triggers an out-of-bounds read and allows lo...
CVE-2009-1072
- EPSS 0.8%
- Published 25.03.2009 01:30:00
- Last modified 09.04.2025 00:30:58
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash o...