CVE-2010-3297
- EPSS 0.1%
- Veröffentlicht 30.09.2010 15:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an EQL...
CVE-2010-3298
- EPSS 0.07%
- Veröffentlicht 30.09.2010 15:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIO...
CVE-2010-2537
- EPSS 0.09%
- Veröffentlicht 30.09.2010 15:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a (1) BTRFS_IOC_CLONE or (2) BTRFS_IOC_CLONE_RANGE ioctl call that specifies this file as a donor.
CVE-2010-2538
- EPSS 0.08%
- Veröffentlicht 30.09.2010 15:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive information via a BTRFS_IOC_CLONE_RANGE ioctl call.
CVE-2010-2943
- EPSS 3.82%
- Veröffentlicht 30.09.2010 15:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assign...
CVE-2010-2478
- EPSS 0.05%
- Veröffentlicht 29.09.2010 17:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.33.7 on 32-bit platforms allows local users to cause a denial of service or possibly have unspecified other impact via an ETHTOOL_GRXCLSRLALL etht...
CVE-2010-2946
- EPSS 0.04%
- Veröffentlicht 29.09.2010 17:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
fs/jfs/xattr.c in the Linux kernel before 2.6.35.2 does not properly handle a certain legacy format for storage of extended attributes, which might allow local users by bypass intended xattr namespace restrictions via an "os2." substring at the begin...
CVE-2010-3084
- EPSS 0.09%
- Veröffentlicht 29.09.2010 17:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in the niu_get_ethtool_tcam_all function in drivers/net/niu.c in the Linux kernel before 2.6.36-rc4 allows local users to cause a denial of service or possibly have unspecified other impact via the ETHTOOL_GRXCLSRLALL ethtool command.
CVE-2010-3310
- EPSS 0.13%
- Veröffentlicht 29.09.2010 17:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple integer signedness errors in net/rose/af_rose.c in the Linux kernel before 2.6.36-rc5-next-20100923 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a rose_getname function...
CVE-2010-3081
- EPSS 21.72%
- Veröffentlicht 24.09.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer, which allows local users to ...