- EPSS 0.61%
- Published 27.05.2010 19:30:01
- Last modified 11.04.2025 00:51:21
Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a call to audioop.lin2lin with ...
CVE-2010-1321
- EPSS 2.2%
- Published 19.05.2010 18:30:03
- Last modified 11.04.2025 00:51:21
The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allo...
CVE-2010-1866
- EPSS 1.56%
- Published 07.05.2010 23:00:01
- Last modified 11.04.2025 00:51:21
The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of service (crash) and possibly trigger memory corruption via a negative chunk size, which bypasses a sig...
- EPSS 0.24%
- Published 07.05.2010 18:30:01
- Last modified 11.04.2025 00:51:21
Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact v...
CVE-2010-0629
- EPSS 2.28%
- Published 07.04.2010 15:30:00
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an inva...
CVE-2010-0840
- EPSS 92.55%
- Published 01.04.2010 16:30:00
- Last modified 11.04.2025 00:51:21
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. ...
CVE-2010-0050
- EPSS 45.13%
- Published 15.03.2010 14:15:32
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improperly nested tags.
CVE-2010-0205
- EPSS 8.13%
- Published 03.03.2010 19:30:00
- Last modified 11.04.2025 00:51:21
The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which...
CVE-2010-0299
- EPSS 0.04%
- Published 22.02.2010 18:30:01
- Last modified 11.04.2025 00:51:21
openSUSE 11.2 installs the devtmpfs root directory with insecure permissions (1777), which allows local users to gain privileges via unspecified vectors.
CVE-2010-0623
- EPSS 0.05%
- Published 15.02.2010 18:30:00
- Last modified 11.04.2025 00:51:21
The futex_lock_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly manage a certain reference count, which allows local users to cause a denial of service (OOPS) via vectors involving an unmount of an ext3 filesystem...