CVE-2011-3439
- EPSS 8.3%
- Veröffentlicht 11.11.2011 18:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
FreeType in CoreGraphics in Apple iOS before 5.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a document.
- EPSS 92.55%
- Veröffentlicht 19.10.2011 21:55:01
- Zuletzt bearbeitet 22.04.2026 13:10:42
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and a...
CVE-2011-3192
- EPSS 90.46%
- Veröffentlicht 29.08.2011 15:55:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as e...
CVE-2011-1526
- EPSS 0.32%
- Veröffentlicht 11.07.2011 20:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, ...
CVE-2011-0419
- EPSS 48.78%
- Veröffentlicht 16.05.2011 17:55:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac...
CVE-2011-1163
- EPSS 0.11%
- Veröffentlicht 10.04.2011 02:51:19
- Zuletzt bearbeitet 29.04.2026 01:13:23
The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from kernel heap memory via vector...
CVE-2011-1083
- EPSS 0.15%
- Veröffentlicht 04.04.2011 12:27:57
- Zuletzt bearbeitet 29.04.2026 01:13:23
The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted application that makes epoll_create a...
- EPSS 45.28%
- Veröffentlicht 02.03.2011 20:00:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions...
CVE-2010-4160
- EPSS 0.11%
- Veröffentlicht 07.01.2011 12:00:48
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple integer overflows in the (1) pppol2tp_sendmsg function in net/l2tp/l2tp_ppp.c, and the (2) l2tp_ip_sendmsg function in net/l2tp/l2tp_ip.c, in the PPPoL2TP and IPoL2TP implementations in the Linux kernel before 2.6.36.2 allow local users to c...
CVE-2010-3876
- EPSS 0.06%
- Veröffentlicht 03.01.2011 20:00:42
- Zuletzt bearbeitet 29.04.2026 01:13:23
net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_RAW capabilit...