CVE-2009-3621
- EPSS 0.04%
- Veröffentlicht 22.10.2009 16:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing ...
CVE-2009-2910
- EPSS 0.05%
- Veröffentlicht 20.10.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 p...
CVE-2009-3612
- EPSS 0.07%
- Veröffentlicht 19.10.2009 20:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensit...
CVE-2009-3289
- EPSS 0.07%
- Veröffentlicht 22.09.2009 10:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions...
CVE-2009-3238
- EPSS 0.24%
- Veröffentlicht 18.09.2009 10:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via v...
CVE-2009-3231
- EPSS 4.96%
- Veröffentlicht 17.09.2009 10:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
- EPSS 3.99%
- Veröffentlicht 08.09.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as...
CVE-2009-2848
- EPSS 0.09%
- Veröffentlicht 18.08.2009 21:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone ...
CVE-2009-2416
- EPSS 0.19%
- Veröffentlicht 11.08.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...
- EPSS 0.43%
- Veröffentlicht 06.08.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop a...