CVE-2010-2798
- EPSS 0.05%
- Veröffentlicht 08.09.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer derefe...
CVE-2010-2297
- EPSS 7.08%
- Veröffentlicht 15.06.2010 18:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
rendering/FixedTableLayout.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an HTML document that has a large colspan attribute...
CVE-2010-2301
- EPSS 0.5%
- Veröffentlicht 15.06.2010 18:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to inject arbitrary web script or HTML via vectors related to the node.innerHTML property of a TEXTAREA ele...
- EPSS 6.11%
- Veröffentlicht 15.06.2010 18:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vectors involving remote fonts in conjunction with sh...
CVE-2010-1770
- EPSS 9.73%
- Veröffentlicht 11.06.2010 19:30:20
- Zuletzt bearbeitet 11.04.2025 00:51:21
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has the IBM1147 character set, wh...
- EPSS 3.16%
- Veröffentlicht 04.11.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathna...
CVE-2009-3621
- EPSS 0.04%
- Veröffentlicht 22.10.2009 16:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing ...
CVE-2009-3289
- EPSS 0.07%
- Veröffentlicht 22.09.2009 10:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions...
CVE-2007-6716
- EPSS 0.04%
- Veröffentlicht 04.09.2008 17:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.
CVE-2008-3275
- EPSS 0.08%
- Veröffentlicht 12.08.2008 23:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denia...