CVE-2009-0946
- EPSS 15.24%
- Veröffentlicht 17.04.2009 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
CVE-2009-1242
- EPSS 0.07%
- Veröffentlicht 06.04.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode e...
CVE-2009-0115
- EPSS 0.08%
- Veröffentlicht 30.03.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket ...
CVE-2009-1072
- EPSS 0.8%
- Veröffentlicht 25.03.2009 01:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash o...
CVE-2009-0848
- EPSS 0.19%
- Veröffentlicht 11.03.2009 14:19:15
- Zuletzt bearbeitet 09.04.2025 00:30:58
Untrusted search path vulnerability in GTK2 in OpenSUSE 11.0 and 11.1 allows local users to execute arbitrary code via a Trojan horse GTK module in an unspecified "relative search path."
CVE-2009-0834
- EPSS 0.06%
- Veröffentlicht 06.03.2009 11:30:02
- Zuletzt bearbeitet 09.04.2025 00:30:58
The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass...
CVE-2009-0749
- EPSS 0.41%
- Veröffentlicht 02.03.2009 20:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Use-after-free vulnerability in the GIFReadNextExtension function in lib/pngxtern/gif/gifread.c in OptiPNG 0.6.2 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a crafted GIF image that causes the r...
CVE-2009-0040
- EPSS 3.94%
- Veröffentlicht 22.02.2009 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a cr...
CVE-2009-0310
- EPSS 0.05%
- Veröffentlicht 18.02.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in SUSE blinux (aka sbl) in SUSE openSUSE 10.3 through 11.0 has unknown impact and attack vectors related to "incoming data and authentication-strings."
- EPSS 0.63%
- Veröffentlicht 12.02.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restric...