CVE-2011-3192
- EPSS 92.84%
- Veröffentlicht 29.08.2011 15:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as e...
CVE-2011-1526
- EPSS 0.23%
- Veröffentlicht 11.07.2011 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, ...
CVE-2011-0419
- EPSS 56.21%
- Veröffentlicht 16.05.2011 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac...
CVE-2011-1163
- EPSS 0.11%
- Veröffentlicht 10.04.2011 02:51:19
- Zuletzt bearbeitet 11.04.2025 00:51:21
The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from kernel heap memory via vector...
CVE-2011-1083
- EPSS 0.18%
- Veröffentlicht 04.04.2011 12:27:57
- Zuletzt bearbeitet 11.04.2025 00:51:21
The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted application that makes epoll_create a...
- EPSS 52.11%
- Veröffentlicht 02.03.2011 20:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions...
CVE-2010-4160
- EPSS 0.16%
- Veröffentlicht 07.01.2011 12:00:48
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple integer overflows in the (1) pppol2tp_sendmsg function in net/l2tp/l2tp_ppp.c, and the (2) l2tp_ip_sendmsg function in net/l2tp/l2tp_ip.c, in the PPPoL2TP and IPoL2TP implementations in the Linux kernel before 2.6.36.2 allow local users to c...
CVE-2010-3876
- EPSS 0.06%
- Veröffentlicht 03.01.2011 20:00:42
- Zuletzt bearbeitet 11.04.2025 00:51:21
net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_RAW capabilit...
CVE-2010-4162
- EPSS 0.08%
- Veröffentlicht 03.01.2011 20:00:42
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (system crash) via a crafted device ioctl to a SCSI device.
CVE-2010-4163
- EPSS 0.08%
- Veröffentlicht 03.01.2011 20:00:42
- Zuletzt bearbeitet 11.04.2025 00:51:21
The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.36.2 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device.