CVE-2010-0006
- EPSS 2.18%
- Veröffentlicht 26.01.2010 18:30:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.32.4, when network namespaces are enabled, allows remote attackers to cause a denial of service (NULL pointer dereference) via an invalid IPv6 jumbogram, a related issue...
CVE-2010-0007
- EPSS 0.07%
- Veröffentlicht 19.01.2010 16:30:01
- Zuletzt bearbeitet 23.04.2026 00:35:47
net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access r...
CVE-2009-4141
- EPSS 0.11%
- Veröffentlicht 19.01.2010 16:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privileges via vectors that include enabling O_ASYNC (aka FASYNC or FIOASYNC) on a locked file, and then cl...
CVE-2009-4536
- EPSS 1.59%
- Veröffentlicht 12.01.2010 17:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel 2.6.32.3 and earlier handles Ethernet frames that exceed the MTU by processing certain trailing payload data as if it were a complete frame, which allows remote attackers to bypas...
CVE-2009-4537
- EPSS 3.72%
- Veröffentlicht 12.01.2010 17:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via...
- EPSS 5.5%
- Veröffentlicht 12.01.2010 17:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a r...
CVE-2009-4410
- EPSS 0.06%
- Veröffentlicht 24.12.2009 16:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The fuse_ioctl_copy_user function in the ioctl handler in fs/fuse/file.c in the Linux kernel 2.6.29-rc1 through 2.6.30.y uses the wrong variable in an argument to the kunmap function, which allows local users to cause a denial of service (panic) via ...
CVE-2009-4138
- EPSS 0.08%
- Veröffentlicht 16.12.2009 19:30:01
- Zuletzt bearbeitet 23.04.2026 00:35:47
drivers/firewire/ohci.c in the Linux kernel before 2.6.32-git9, when packet-per-buffer mode is used, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unknown other impact via an unspecified ...
CVE-2009-4131
- EPSS 0.08%
- Veröffentlicht 13.12.2009 01:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementation in the ext4 filesystem in the Linux kernel before 2.6.32-git6 allows local users to overwrite arbitrary files via a crafted request, related to insufficient checks for file permissions.
CVE-2009-4306
- EPSS 0.05%
- Veröffentlicht 13.12.2009 01:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Unspecified vulnerability in the EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementation in the ext4 filesystem in the Linux kernel 2.6.32-git6 and earlier allows local users to cause a denial of service (filesystem corruption) via unknown vectors,...