CVE-2012-0053
- EPSS 70.5%
- Veröffentlicht 28.01.2012 04:05:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors i...
CVE-2012-0031
- EPSS 2.18%
- Veröffentlicht 18.01.2012 20:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memor...
CVE-2011-3389
- EPSS 4.51%
- Veröffentlicht 06.09.2011 19:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man...
CVE-2011-2213
- EPSS 0.06%
- Veröffentlicht 29.08.2011 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The inet_diag_bc_audit function in net/ipv4/inet_diag.c in the Linux kernel before 2.6.39.3 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE in...
CVE-2011-2821
- EPSS 2.28%
- Veröffentlicht 29.08.2011 15:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.
CVE-2011-2492
- EPSS 0.06%
- Veröffentlicht 28.07.2011 22:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The bluetooth subsystem in the Linux kernel before 3.0-rc4 does not properly initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel memory via a crafted getsockopt system call, related to ...
CVE-2011-1093
- EPSS 1.22%
- Veröffentlicht 18.07.2011 22:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The dccp_rcv_state_process function in net/dccp/input.c in the Datagram Congestion Control Protocol (DCCP) implementation in the Linux kernel before 2.6.38 does not properly handle packets for a CLOSED endpoint, which allows remote attackers to cause...
CVE-2011-1745
- EPSS 0.04%
- Veröffentlicht 09.05.2011 19:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the agp_generic_insert_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_BIND agp_ioctl ioctl c...
CVE-2011-1746
- EPSS 0.04%
- Veröffentlicht 09.05.2011 19:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple integer overflows in the (1) agp_allocate_memory and (2) agp_create_user_memory functions in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allow local users to trigger buffer overflows, and consequently cause a denial of ser...
CVE-2011-2022
- EPSS 0.04%
- Veröffentlicht 09.05.2011 19:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The agp_generic_remove_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 does not validate a certain start parameter, which allows local users to gain privileges or cause a denial of service (system crash) via a crafte...