CVE-2010-3298
- EPSS 0.07%
- Veröffentlicht 30.09.2010 15:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIO...
CVE-2010-2537
- EPSS 0.09%
- Veröffentlicht 30.09.2010 15:00:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a (1) BTRFS_IOC_CLONE or (2) BTRFS_IOC_CLONE_RANGE ioctl call that specifies this file as a donor.
CVE-2010-2538
- EPSS 0.08%
- Veröffentlicht 30.09.2010 15:00:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive information via a BTRFS_IOC_CLONE_RANGE ioctl call.
CVE-2010-2943
- EPSS 3.82%
- Veröffentlicht 30.09.2010 15:00:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assign...
CVE-2010-2478
- EPSS 0.09%
- Veröffentlicht 29.09.2010 17:00:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
Integer overflow in the ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.33.7 on 32-bit platforms allows local users to cause a denial of service or possibly have unspecified other impact via an ETHTOOL_GRXCLSRLALL etht...
CVE-2010-2946
- EPSS 0.04%
- Veröffentlicht 29.09.2010 17:00:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
fs/jfs/xattr.c in the Linux kernel before 2.6.35.2 does not properly handle a certain legacy format for storage of extended attributes, which might allow local users by bypass intended xattr namespace restrictions via an "os2." substring at the begin...
CVE-2010-3084
- EPSS 0.09%
- Veröffentlicht 29.09.2010 17:00:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
Buffer overflow in the niu_get_ethtool_tcam_all function in drivers/net/niu.c in the Linux kernel before 2.6.36-rc4 allows local users to cause a denial of service or possibly have unspecified other impact via the ETHTOOL_GRXCLSRLALL ethtool command.
CVE-2010-3310
- EPSS 0.13%
- Veröffentlicht 29.09.2010 17:00:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple integer signedness errors in net/rose/af_rose.c in the Linux kernel before 2.6.36-rc5-next-20100923 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a rose_getname function...
CVE-2010-3081
- EPSS 7.25%
- Veröffentlicht 24.09.2010 20:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer, which allows local users to ...
CVE-2010-3301
- EPSS 6.61%
- Veröffentlicht 22.09.2010 19:00:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero extend the %eax register after the 32-bit entry path to ptrace is used, which allows local users...