CVE-2009-3939
- EPSS 0.04%
- Published 16.11.2009 19:30:01
- Last modified 09.04.2025 00:30:58
The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
- EPSS 3.44%
- Published 04.11.2009 15:30:00
- Last modified 09.04.2025 00:30:58
Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathna...
CVE-2009-3616
- EPSS 0.86%
- Published 23.10.2009 18:30:00
- Last modified 09.04.2025 00:30:58
Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a VNC client and then (1) disconnecting during data tr...
CVE-2009-2910
- EPSS 0.05%
- Published 20.10.2009 17:30:00
- Last modified 09.04.2025 00:30:58
arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 p...
CVE-2009-3228
- EPSS 0.08%
- Published 19.10.2009 20:00:00
- Last modified 09.04.2025 00:30:58
The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users ...
CVE-2009-2698
- EPSS 23.09%
- Published 27.08.2009 17:30:00
- Last modified 09.04.2025 00:30:58
The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vecto...
CVE-2009-2848
- EPSS 0.09%
- Published 18.08.2009 21:00:00
- Last modified 09.04.2025 00:30:58
The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone ...
CVE-2009-2692
- EPSS 18.38%
- Published 14.08.2009 15:16:27
- Last modified 09.04.2025 00:30:58
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using ...
CVE-2009-1891
- EPSS 20.93%
- Published 10.07.2009 15:30:00
- Last modified 09.04.2025 00:30:58
The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
CVE-2009-1890
- EPSS 21.52%
- Published 05.07.2009 16:30:00
- Last modified 09.04.2025 00:30:58
The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which al...