CVE-2011-0711
- EPSS 0.06%
- Veröffentlicht 01.03.2011 23:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOME...
CVE-2010-4649
- EPSS 0.07%
- Veröffentlicht 18.02.2011 20:00:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
Integer overflow in the ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large val...
CVE-2011-1044
- EPSS 0.06%
- Veröffentlicht 18.02.2011 20:00:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
The ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 does not initialize a certain response buffer, which allows local users to obtain potentially sensitive information from kernel memory via vector...
CVE-2009-2698
- EPSS 26.12%
- Veröffentlicht 27.08.2009 17:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vecto...
CVE-2009-2692
- EPSS 17.56%
- Veröffentlicht 14.08.2009 15:16:27
- Zuletzt bearbeitet 23.04.2026 00:35:47
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using ...
CVE-2009-1891
- EPSS 18.85%
- Veröffentlicht 10.07.2009 15:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
CVE-2009-1890
- EPSS 37.87%
- Veröffentlicht 05.07.2009 16:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which al...
CVE-2009-1837
- EPSS 2.18%
- Veröffentlicht 12.06.2009 21:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transition during Java applet loading,...
CVE-2009-0834
- EPSS 0.05%
- Veröffentlicht 06.03.2009 11:30:02
- Zuletzt bearbeitet 23.04.2026 00:35:47
The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass...