CVE-2009-3238
- EPSS 1.63%
- Veröffentlicht 18.09.2009 10:30:01
- Zuletzt bearbeitet 16.06.2026 23:11:12
The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via v...
CVE-2009-1883
- EPSS 0.34%
- Veröffentlicht 18.09.2009 10:30:00
- Zuletzt bearbeitet 16.06.2026 23:08:16
The z90crypt_unlocked_ioctl function in the z90crypt driver in the Linux kernel 2.6.9 does not perform a capability check for the Z90QUIESCE operation, which allows local users to leverage euid 0 privileges to force a driver outage.
CVE-2009-3234
- EPSS 1.8%
- Veröffentlicht 17.09.2009 10:30:01
- Zuletzt bearbeitet 16.06.2026 23:11:11
Buffer overflow in the perf_copy_attr function in kernel/perf_counter.c in the Linux kernel 2.6.31-rc1 allows local users to cause a denial of service (crash) and execute arbitrary code via a "big size data" to the perf_counter_open system call.
CVE-2009-2903
- EPSS 3.85%
- Veröffentlicht 15.09.2009 22:30:00
- Zuletzt bearbeitet 16.06.2026 23:10:28
Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (me...
CVE-2009-3043
- EPSS 0.85%
- Veröffentlicht 02.09.2009 17:30:00
- Zuletzt bearbeitet 16.06.2026 23:10:47
The tty_ldisc_hangup function in drivers/char/tty_ldisc.c in the Linux kernel 2.6.31-rc before 2.6.31-rc8 allows local users to cause a denial of service (system crash, sometimes preceded by a NULL pointer dereference) or possibly gain privileges via...
CVE-2009-2695
- EPSS 0.51%
- Veröffentlicht 28.08.2009 15:30:00
- Zuletzt bearbeitet 16.06.2026 23:10:02
The Linux kernel before 2.6.31-rc7 does not properly prevent mmap operations that target page zero and other low memory addresses, which allows local users to gain privileges by exploiting NULL pointer dereference vulnerabilities, related to (1) the ...
CVE-2009-3001
- EPSS 1.02%
- Veröffentlicht 28.08.2009 15:30:00
- Zuletzt bearbeitet 16.06.2026 23:10:41
The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain data structure, which allows local users to read the contents of some kernel memory locations by calling getsockname on an AF_LLC...
CVE-2009-3002
- EPSS 1.03%
- Veröffentlicht 28.08.2009 15:30:00
- Zuletzt bearbeitet 16.06.2026 23:10:42
The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_APPLETALK socket, related to th...
CVE-2009-2698
- EPSS 7.12%
- Veröffentlicht 27.08.2009 17:30:00
- Zuletzt bearbeitet 16.06.2026 23:10:03
The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vecto...
CVE-2009-2844
- EPSS 3.36%
- Veröffentlicht 18.08.2009 21:00:00
- Zuletzt bearbeitet 16.06.2026 23:10:20
cfg80211 in net/wireless/scan.c in the Linux kernel 2.6.30-rc1 and other versions before 2.6.31-rc6 allows remote attackers to cause a denial of service (crash) via a sequence of beacon frames in which one frame omits an SSID Information Element (IE)...