CVE-2012-0031
- EPSS 2.18%
- Veröffentlicht 18.01.2012 20:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memor...
CVE-2011-3389
- EPSS 4.51%
- Veröffentlicht 06.09.2011 19:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man...
CVE-2011-1776
- EPSS 0.12%
- Veröffentlicht 06.09.2011 16:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The is_gpt_valid function in fs/partitions/efi.c in the Linux kernel before 2.6.39 does not check the size of an Extensible Firmware Interface (EFI) GUID Partition Table (GPT) entry, which allows physically proximate attackers to cause a denial of se...
CVE-2011-1163
- EPSS 0.11%
- Veröffentlicht 10.04.2011 02:51:19
- Zuletzt bearbeitet 11.04.2025 00:51:21
The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from kernel heap memory via vector...
CVE-2011-0695
- EPSS 0.44%
- Veröffentlicht 15.03.2011 17:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in Linux kernel 2.6.x allows remote attackers to cause a denial of service (panic) by sending an InfiniBand request while other request handlers a...
CVE-2011-0711
- EPSS 0.06%
- Veröffentlicht 01.03.2011 23:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOME...
CVE-2010-4649
- EPSS 0.07%
- Veröffentlicht 18.02.2011 20:00:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large val...
CVE-2011-1044
- EPSS 0.06%
- Veröffentlicht 18.02.2011 20:00:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 does not initialize a certain response buffer, which allows local users to obtain potentially sensitive information from kernel memory via vector...
CVE-2009-2698
- EPSS 23.09%
- Veröffentlicht 27.08.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vecto...
CVE-2009-2692
- EPSS 18.38%
- Veröffentlicht 14.08.2009 15:16:27
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using ...