CVE-2010-0727
- EPSS 0.08%
- Veröffentlicht 16.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The gfs2_lock function in the Linux kernel before 2.6.34-rc1-next-20100312, and the gfs_lock function in the Linux kernel on Red Hat Enterprise Linux (RHEL) 5 and 6, does not properly remove POSIX locks on files that are setgid without group-execute ...
CVE-2010-0729
- EPSS 0.05%
- Veröffentlicht 16.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
A certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 4 on the ia64 platform allows local users to use ptrace on an arbitrary process, and consequently gain privileges, via vectors related to a missing ptrace_check_attach ca...
CVE-2010-0302
- EPSS 5.29%
- Veröffentlicht 05.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denia...
CVE-2009-3556
- EPSS 0.03%
- Veröffentlicht 27.01.2010 17:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport...
CVE-2010-0013
- EPSS 12.31%
- Veröffentlicht 09.01.2010 18:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) requ...
CVE-2009-3553
- EPSS 9.85%
- Veröffentlicht 20.11.2009 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash ...
CVE-2009-2416
- EPSS 0.19%
- Veröffentlicht 11.08.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...
CVE-2009-1893
- EPSS 0.08%
- Veröffentlicht 17.07.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file, related to the "dhcpd -t" command.
CVE-2009-1837
- EPSS 2.18%
- Veröffentlicht 12.06.2009 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transition during Java applet loading,...
- EPSS 50.18%
- Veröffentlicht 09.04.2009 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code...