CVE-2009-3238
- EPSS 0.24%
- Published 18.09.2009 10:30:01
- Last modified 09.04.2025 00:30:58
The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via v...
CVE-2009-2903
- EPSS 3.77%
- Published 15.09.2009 22:30:00
- Last modified 09.04.2025 00:30:58
Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (me...
- EPSS 3.99%
- Published 08.09.2009 18:30:00
- Last modified 09.04.2025 00:30:58
The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as...
CVE-2009-2698
- EPSS 23.09%
- Published 27.08.2009 17:30:00
- Last modified 09.04.2025 00:30:58
The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vecto...
CVE-2009-2848
- EPSS 0.09%
- Published 18.08.2009 21:00:00
- Last modified 09.04.2025 00:30:58
The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone ...
CVE-2009-2472
- EPSS 0.7%
- Published 22.07.2009 18:30:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, re...
CVE-2009-1961
- EPSS 0.13%
- Published 08.06.2009 01:00:00
- Last modified 09.04.2025 00:30:58
The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of ...
CVE-2009-1185
- EPSS 89.27%
- Published 17.04.2009 14:30:00
- Last modified 09.04.2025 00:30:58
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
CVE-2009-1186
- EPSS 0.09%
- Published 17.04.2009 14:30:00
- Last modified 09.04.2025 00:30:58
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
CVE-2009-0115
- EPSS 0.08%
- Published 30.03.2009 16:30:00
- Last modified 09.04.2025 00:30:58
The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket ...