CVE-2009-1242
- EPSS 0.47%
- Veröffentlicht 06.04.2009 14:30:00
- Zuletzt bearbeitet 16.06.2026 23:06:50
The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode e...
CVE-2009-1243
- EPSS 0.27%
- Veröffentlicht 06.04.2009 14:30:00
- Zuletzt bearbeitet 16.06.2026 23:06:50
net/ipv4/udp.c in the Linux kernel before 2.6.29.1 performs an unlocking step in certain incorrect circumstances, which allows local users to cause a denial of service (panic) by reading zero bytes from the /proc/net/udp file and unspecified other fi...
CVE-2009-0787
- EPSS 0.39%
- Veröffentlicht 25.03.2009 01:30:00
- Zuletzt bearbeitet 16.06.2026 23:05:48
The ecryptfs_write_metadata_to_contents function in the eCryptfs functionality in the Linux kernel 2.6.28 before 2.6.28.9 uses an incorrect size when writing kernel memory to an eCryptfs file header, which triggers an out-of-bounds read and allows lo...
CVE-2009-1072
- EPSS 0.43%
- Veröffentlicht 25.03.2009 01:30:00
- Zuletzt bearbeitet 16.06.2026 23:06:26
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash o...
CVE-2009-1046
- EPSS 0.78%
- Veröffentlicht 23.03.2009 16:30:01
- Zuletzt bearbeitet 16.06.2026 23:06:23
The console selection feature in the Linux kernel 2.6.28 before 2.6.28.4, 2.6.25, and possibly earlier versions, when the UTF-8 console is used, allows physically proximate attackers to cause a denial of service (memory corruption) by selecting a sma...
CVE-2009-0935
- EPSS 0.27%
- Veröffentlicht 18.03.2009 02:00:08
- Zuletzt bearbeitet 16.06.2026 23:06:08
The inotify_read function in the Linux kernel 2.6.27 to 2.6.27.13, 2.6.28 to 2.6.28.2, and 2.6.29-rc3 allows local users to cause a denial of service (OOPS) via a read with an invalid address to an inotify instance, which causes the device's event li...
CVE-2009-0778
- EPSS 4.62%
- Veröffentlicht 12.03.2009 15:20:49
- Zuletzt bearbeitet 16.06.2026 23:05:47
The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of a...
CVE-2009-0859
- EPSS 0.37%
- Veröffentlicht 09.03.2009 21:30:00
- Zuletzt bearbeitet 16.06.2026 23:05:58
The shm_get_stat function in ipc/shm.c in the shm subsystem in the Linux kernel before 2.6.28.5, when CONFIG_SHMEM is disabled, misinterprets the data type of an inode, which allows local users to cause a denial of service (system hang) via an SHM_IN...
CVE-2009-0834
- EPSS 0.44%
- Veröffentlicht 06.03.2009 11:30:02
- Zuletzt bearbeitet 16.06.2026 23:05:54
The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass...
CVE-2009-0835
- EPSS 0.93%
- Veröffentlicht 06.03.2009 11:30:02
- Zuletzt bearbeitet 16.06.2026 23:05:54
The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform, when CONFIG_SECCOMP is enabled, does not properly handle (1) a 32-bit process making a 64-bit syscall or (2)...