CVE-2010-3081
- EPSS 21.72%
- Veröffentlicht 24.09.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer, which allows local users to ...
CVE-2010-3078
- EPSS 0.05%
- Veröffentlicht 21.09.2010 18:00:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an...
CVE-2010-2942
- EPSS 0.06%
- Veröffentlicht 21.09.2010 18:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive in...
CVE-2010-2798
- EPSS 0.05%
- Veröffentlicht 08.09.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer derefe...
CVE-2010-2524
- EPSS 0.08%
- Veröffentlicht 08.09.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace helper, which allows local user...
CVE-2010-2492
- EPSS 0.03%
- Veröffentlicht 08.09.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors.
CVE-2010-2066
- EPSS 0.06%
- Veröffentlicht 08.09.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor.
CVE-2009-3080
- EPSS 0.07%
- Veröffentlicht 20.11.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.
- EPSS 3.44%
- Veröffentlicht 04.11.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathna...
CVE-2009-3621
- EPSS 0.04%
- Veröffentlicht 22.10.2009 16:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing ...