CVE-2011-3192
- EPSS 92.84%
- Published 29.08.2011 15:55:02
- Last modified 11.04.2025 00:51:21
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as e...
CVE-2011-1526
- EPSS 0.23%
- Published 11.07.2011 20:55:01
- Last modified 11.04.2025 00:51:21
ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, ...
CVE-2011-0419
- EPSS 56.21%
- Published 16.05.2011 17:55:02
- Last modified 11.04.2025 00:51:21
Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac...
CVE-2011-1163
- EPSS 0.11%
- Published 10.04.2011 02:51:19
- Last modified 11.04.2025 00:51:21
The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from kernel heap memory via vector...
CVE-2011-1083
- EPSS 0.18%
- Published 04.04.2011 12:27:57
- Last modified 11.04.2025 00:51:21
The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted application that makes epoll_create a...
- EPSS 36.87%
- Published 02.03.2011 20:00:01
- Last modified 11.04.2025 00:51:21
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions...
CVE-2010-4160
- EPSS 0.16%
- Published 07.01.2011 12:00:48
- Last modified 11.04.2025 00:51:21
Multiple integer overflows in the (1) pppol2tp_sendmsg function in net/l2tp/l2tp_ppp.c, and the (2) l2tp_ip_sendmsg function in net/l2tp/l2tp_ip.c, in the PPPoL2TP and IPoL2TP implementations in the Linux kernel before 2.6.36.2 allow local users to c...
CVE-2010-3876
- EPSS 0.06%
- Published 03.01.2011 20:00:42
- Last modified 11.04.2025 00:51:21
net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_RAW capabilit...
CVE-2010-4162
- EPSS 0.08%
- Published 03.01.2011 20:00:42
- Last modified 11.04.2025 00:51:21
Multiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (system crash) via a crafted device ioctl to a SCSI device.
CVE-2010-4163
- EPSS 0.08%
- Published 03.01.2011 20:00:42
- Last modified 11.04.2025 00:51:21
The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.36.2 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device.