CVE-2009-2910
- EPSS 0.41%
- Veröffentlicht 20.10.2009 17:30:00
- Zuletzt bearbeitet 16.06.2026 23:10:29
arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 p...
CVE-2005-4881
- EPSS 0.38%
- Veröffentlicht 19.10.2009 20:00:00
- Zuletzt bearbeitet 16.06.2026 22:19:39
The netlink subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.13-rc1 does not initialize certain padding fields in structures, which might allow local users to obtain sensitive information from kernel memory via unspecified vec...
CVE-2009-3228
- EPSS 0.4%
- Veröffentlicht 19.10.2009 20:00:00
- Zuletzt bearbeitet 16.06.2026 23:11:10
The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users ...
CVE-2009-3612
- EPSS 0.4%
- Veröffentlicht 19.10.2009 20:00:00
- Zuletzt bearbeitet 16.06.2026 23:12:00
The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensit...
CVE-2009-3613
- EPSS 12.46%
- Veröffentlicht 19.10.2009 20:00:00
- Zuletzt bearbeitet 16.06.2026 23:12:01
The swiotlb functionality in the r8169 driver in drivers/net/r8169.c in the Linux kernel before 2.6.27.22 allows remote attackers to cause a denial of service (IOMMU space exhaustion and system crash) by using jumbo frames for a large amount of netwo...
CVE-2009-2908
- EPSS 1.24%
- Veröffentlicht 13.10.2009 10:30:00
- Zuletzt bearbeitet 16.06.2026 23:10:28
The d_delete function in fs/ecryptfs/inode.c in eCryptfs in the Linux kernel 2.6.31 allows local users to cause a denial of service (kernel OOPS) and possibly execute arbitrary code via unspecified vectors that cause a "negative dentry" and trigger a...
CVE-2009-3286
- EPSS 0.47%
- Veröffentlicht 22.09.2009 10:30:00
- Zuletzt bearbeitet 16.06.2026 23:11:18
NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privi...
CVE-2009-3288
- EPSS 0.44%
- Veröffentlicht 22.09.2009 10:30:00
- Zuletzt bearbeitet 16.06.2026 23:11:18
The sg_build_indirect function in drivers/scsi/sg.c in Linux kernel 2.6.28-rc1 through 2.6.31-rc8 uses an incorrect variable when accessing an array, which allows local users to cause a denial of service (kernel OOPS and NULL pointer dereference), as...
CVE-2009-3290
- EPSS 0.4%
- Veröffentlicht 22.09.2009 10:30:00
- Zuletzt bearbeitet 16.06.2026 23:11:18
The kvm_emulate_hypercall function in arch/x86/kvm/x86.c in KVM in the Linux kernel 2.6.25-rc1, and other versions before 2.6.31, when running on x86 systems, does not prevent access to MMU hypercalls from ring 0, which allows local guest OS users to...
CVE-2009-3280
- EPSS 3.25%
- Veröffentlicht 21.09.2009 19:30:00
- Zuletzt bearbeitet 16.06.2026 23:11:17
Integer signedness error in the find_ie function in net/wireless/scan.c in the cfg80211 subsystem in the Linux kernel before 2.6.31.1-rc1 allows remote attackers to cause a denial of service (soft lockup) via malformed packets.