CVE-2009-3939
- EPSS 0.04%
- Published 16.11.2009 19:30:01
- Last modified 09.04.2025 00:30:58
The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
CVE-2009-3620
- EPSS 0.07%
- Published 22.10.2009 16:00:00
- Last modified 09.04.2025 00:30:58
The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash...
CVE-2009-2910
- EPSS 0.05%
- Published 20.10.2009 17:30:00
- Last modified 09.04.2025 00:30:58
arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 p...
CVE-2009-3612
- EPSS 0.07%
- Published 19.10.2009 20:00:00
- Last modified 09.04.2025 00:30:58
The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensit...
CVE-2009-3238
- EPSS 0.24%
- Published 18.09.2009 10:30:01
- Last modified 09.04.2025 00:30:58
The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via v...
CVE-2009-3231
- EPSS 4.96%
- Published 17.09.2009 10:30:01
- Last modified 09.04.2025 00:30:58
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
CVE-2009-2903
- EPSS 3.77%
- Published 15.09.2009 22:30:00
- Last modified 09.04.2025 00:30:58
Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (me...
- EPSS 3.99%
- Published 08.09.2009 18:30:00
- Last modified 09.04.2025 00:30:58
The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as...
CVE-2009-2698
- EPSS 23.09%
- Published 27.08.2009 17:30:00
- Last modified 09.04.2025 00:30:58
The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vecto...
CVE-2009-2848
- EPSS 0.09%
- Published 18.08.2009 21:00:00
- Last modified 09.04.2025 00:30:58
The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone ...