CVE-2009-2848
- EPSS 0.09%
- Veröffentlicht 18.08.2009 21:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone ...
CVE-2009-2416
- EPSS 0.19%
- Veröffentlicht 11.08.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...
CVE-2009-1630
- EPSS 0.11%
- Veröffentlicht 14.05.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass pe...
CVE-2009-1072
- EPSS 0.8%
- Veröffentlicht 25.03.2009 01:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash o...
CVE-2009-0778
- EPSS 1.65%
- Veröffentlicht 12.03.2009 15:20:49
- Zuletzt bearbeitet 09.04.2025 00:30:58
The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of a...
CVE-2009-0034
- EPSS 0.05%
- Veröffentlicht 30.01.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file...
CVE-2008-4279
- EPSS 0.07%
- Veröffentlicht 06.10.2008 19:54:36
- Zuletzt bearbeitet 09.04.2025 00:30:58
The CPU hardware emulation for 64-bit guest operating systems in VMware Workstation 6.0.x before 6.0.5 build 109488 and 5.x before 5.5.8 build 108000; Player 2.0.x before 2.0.5 build 109488 and 1.x before 1.0.8; Server 1.x before 1.0.7 build 108231; ...
CVE-2008-3281
- EPSS 0.8%
- Veröffentlicht 27.08.2008 20:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
CVE-2008-2100
- EPSS 0.15%
- Veröffentlicht 05.06.2008 20:32:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x, VMware ACE 2.x, VMware Server 1.x, VMware Fusion 1.x, VMware ESXi 3.5, and VMware ESX 3.0.1 through 3.5 allow guest OS u...
CVE-2008-0967
- EPSS 0.07%
- Veröffentlicht 05.06.2008 20:32:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build...