CVE-2009-4005
- EPSS 0.05%
- Published 20.11.2009 02:30:01
- Last modified 09.04.2025 00:30:58
The collect_rx_frame function in drivers/isdn/hisax/hfc_usb.c in the Linux kernel before 2.6.32-rc7 allows attackers to have an unspecified impact via a crafted HDLC packet that arrives over ISDN and triggers a buffer under-read.
CVE-2009-4004
- EPSS 0.05%
- Published 20.11.2009 02:30:00
- Last modified 09.04.2025 00:30:58
Buffer overflow in the kvm_vcpu_ioctl_x86_setup_mce function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.32-rc7 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a KVM_X8...
CVE-2009-3939
- EPSS 0.04%
- Published 16.11.2009 19:30:01
- Last modified 09.04.2025 00:30:58
The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
CVE-2009-3888
- EPSS 0.12%
- Published 16.11.2009 19:30:00
- Last modified 09.04.2025 00:30:58
The do_mmap_pgoff function in mm/nommu.c in the Linux kernel before 2.6.31.6, when the CPU lacks a memory management unit, allows local users to cause a denial of service (OOPS) via an application that attempts to allocate a large amount of memory.
CVE-2009-3889
- EPSS 0.05%
- Published 16.11.2009 19:30:00
- Last modified 09.04.2025 00:30:58
The dbg_lvl file for the megaraid_sas driver in the Linux kernel before 2.6.27 has world-writable permissions, which allows local users to change the (1) behavior and (2) logging level of the driver by modifying this file.
CVE-2009-3726
- EPSS 5.79%
- Published 09.11.2009 19:30:00
- Last modified 09.04.2025 00:30:58
The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) by sending a certain response containing incorrect ...
CVE-2009-3725
- EPSS 0.05%
- Published 06.11.2009 15:30:00
- Last modified 09.04.2025 00:30:58
The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restric...
- EPSS 3.44%
- Published 04.11.2009 15:30:00
- Last modified 09.04.2025 00:30:58
Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathna...
CVE-2009-3624
- EPSS 0.06%
- Published 02.11.2009 15:30:00
- Last modified 09.04.2025 00:30:58
The get_instantiation_keyring function in security/keys/keyctl.c in the KEYS subsystem in the Linux kernel before 2.6.32-rc5 does not properly maintain the reference count of a keyring, which allows local users to gain privileges or cause a denial of...
CVE-2009-3623
- EPSS 1.41%
- Published 30.10.2009 20:30:00
- Last modified 09.04.2025 00:30:58
The lookup_cb_cred function in fs/nfsd/nfs4callback.c in the nfsd4 subsystem in the Linux kernel before 2.6.31.2 attempts to access a credentials cache even when a client specifies the AUTH_NULL authentication flavor, which allows remote attackers to...