CVE-2009-3612
- EPSS 0.07%
- Veröffentlicht 19.10.2009 20:00:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensit...
CVE-2009-3613
- EPSS 5.65%
- Veröffentlicht 19.10.2009 20:00:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The swiotlb functionality in the r8169 driver in drivers/net/r8169.c in the Linux kernel before 2.6.27.22 allows remote attackers to cause a denial of service (IOMMU space exhaustion and system crash) by using jumbo frames for a large amount of netwo...
CVE-2009-2908
- EPSS 2.96%
- Veröffentlicht 13.10.2009 10:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The d_delete function in fs/ecryptfs/inode.c in eCryptfs in the Linux kernel 2.6.31 allows local users to cause a denial of service (kernel OOPS) and possibly execute arbitrary code via unspecified vectors that cause a "negative dentry" and trigger a...
CVE-2009-3286
- EPSS 0.1%
- Veröffentlicht 22.09.2009 10:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privi...
CVE-2009-3288
- EPSS 0.08%
- Veröffentlicht 22.09.2009 10:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The sg_build_indirect function in drivers/scsi/sg.c in Linux kernel 2.6.28-rc1 through 2.6.31-rc8 uses an incorrect variable when accessing an array, which allows local users to cause a denial of service (kernel OOPS and NULL pointer dereference), as...
CVE-2009-3290
- EPSS 0.05%
- Veröffentlicht 22.09.2009 10:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The kvm_emulate_hypercall function in arch/x86/kvm/x86.c in KVM in the Linux kernel 2.6.25-rc1, and other versions before 2.6.31, when running on x86 systems, does not prevent access to MMU hypercalls from ring 0, which allows local guest OS users to...
CVE-2009-3280
- EPSS 1.63%
- Veröffentlicht 21.09.2009 19:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Integer signedness error in the find_ie function in net/wireless/scan.c in the cfg80211 subsystem in the Linux kernel before 2.6.31.1-rc1 allows remote attackers to cause a denial of service (soft lockup) via malformed packets.
CVE-2009-3238
- EPSS 0.24%
- Veröffentlicht 18.09.2009 10:30:01
- Zuletzt bearbeitet 23.04.2026 00:35:47
The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via v...
CVE-2009-1883
- EPSS 0.08%
- Veröffentlicht 18.09.2009 10:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The z90crypt_unlocked_ioctl function in the z90crypt driver in the Linux kernel 2.6.9 does not perform a capability check for the Z90QUIESCE operation, which allows local users to leverage euid 0 privileges to force a driver outage.
CVE-2009-3234
- EPSS 0.86%
- Veröffentlicht 17.09.2009 10:30:01
- Zuletzt bearbeitet 23.04.2026 00:35:47
Buffer overflow in the perf_copy_attr function in kernel/perf_counter.c in the Linux kernel 2.6.31-rc1 allows local users to cause a denial of service (crash) and execute arbitrary code via a "big size data" to the perf_counter_open system call.