- EPSS 3.37%
- Veröffentlicht 03.01.2011 20:00:41
- Zuletzt bearbeitet 11.04.2025 00:51:21
The X.25 implementation in the Linux kernel before 2.6.36.2 does not properly parse facilities, which allows remote attackers to cause a denial of service (heap memory corruption and panic) or possibly have unspecified other impact via malformed (1) ...
CVE-2010-4258
- EPSS 2.52%
- Veröffentlicht 30.12.2010 19:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain pri...
CVE-2010-4158
- EPSS 0.21%
- Veröffentlicht 30.12.2010 19:00:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check whether a certain memory location has been initialized before executing a (1) BPF_S_LD_MEM or (2) BPF_S_LDX_MEM instruction, which allows local users t...
- EPSS 0.1%
- Veröffentlicht 29.12.2010 18:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.36.2 on 64-bit platforms might allow local users to cause a denial ...
CVE-2010-4347
- EPSS 7.39%
- Veröffentlicht 22.12.2010 21:00:19
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain privileges by placing a custom ACPI method in the ACPI interpreter tables, related to the acpi_debugfs_i...
CVE-2010-4344
- EPSS 61.46%
- Veröffentlicht 14.12.2010 16:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted hea...
CVE-2010-4345
- EPSS 4.02%
- Veröffentlicht 14.12.2010 16:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory direct...
CVE-2010-4157
- EPSS 0.11%
- Veröffentlicht 10.12.2010 19:00:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the ioc_general function in drivers/scsi/gdth.c in the Linux kernel before 2.6.36.1 on 64-bit platforms allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large argu...
CVE-2010-3861
- EPSS 0.05%
- Veröffentlicht 10.12.2010 19:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive information via an ETHTOOL_GRXCLSRLALL ethtool command...
CVE-2010-4494
- EPSS 1.62%
- Veröffentlicht 07.12.2010 21:00:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath...