CVE-2010-3859
- EPSS 0.1%
- Published 29.12.2010 18:00:02
- Last modified 11.04.2025 00:51:21
Multiple integer signedness errors in the TIPC implementation in the Linux kernel before 2.6.36.2 allow local users to gain privileges via a crafted sendmsg call that triggers a heap-based buffer overflow, related to the tipc_msg_build function in ne...
- EPSS 0.1%
- Published 29.12.2010 18:00:02
- Last modified 11.04.2025 00:51:21
Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.36.2 on 64-bit platforms might allow local users to cause a denial ...
CVE-2010-4343
- EPSS 0.07%
- Published 29.12.2010 18:00:02
- Last modified 11.04.2025 00:51:21
drivers/scsi/bfa/bfa_core.c in the Linux kernel before 2.6.35 does not initialize a certain port data structure, which allows local users to cause a denial of service (system crash) via read operations on an fc_host statistics file.
CVE-2010-4565
- EPSS 0.09%
- Published 29.12.2010 18:00:02
- Last modified 11.04.2025 00:51:21
The bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel 2.6.36 and earlier creates a publicly accessible file with a filename containing a kernel memory address, wh...
CVE-2010-3881
- EPSS 0.07%
- Published 23.12.2010 18:00:02
- Last modified 11.04.2025 00:51:21
arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.
CVE-2010-4346
- EPSS 0.06%
- Published 22.12.2010 21:00:19
- Last modified 11.04.2025 00:51:21
The install_special_mapping function in mm/mmap.c in the Linux kernel before 2.6.37-rc6 does not make an expected security_file_mmap function call, which allows local users to bypass intended mmap_min_addr restrictions and possibly conduct NULL point...
CVE-2010-4347
- EPSS 7.39%
- Published 22.12.2010 21:00:19
- Last modified 11.04.2025 00:51:21
The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain privileges by placing a custom ACPI method in the ACPI interpreter tables, related to the acpi_debugfs_i...
CVE-2010-4157
- EPSS 0.11%
- Published 10.12.2010 19:00:05
- Last modified 11.04.2025 00:51:21
Integer overflow in the ioc_general function in drivers/scsi/gdth.c in the Linux kernel before 2.6.36.1 on 64-bit platforms allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large argu...
CVE-2010-3861
- EPSS 0.05%
- Published 10.12.2010 19:00:04
- Last modified 11.04.2025 00:51:21
The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive information via an ETHTOOL_GRXCLSRLALL ethtool command...
CVE-2010-3880
- EPSS 0.13%
- Published 10.12.2010 19:00:04
- Last modified 11.04.2025 00:51:21
net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message t...