CVE-2009-3080
- EPSS 0.42%
- Veröffentlicht 20.11.2009 17:30:00
- Zuletzt bearbeitet 16.06.2026 23:10:53
Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.
- EPSS 4.89%
- Veröffentlicht 04.11.2009 15:30:00
- Zuletzt bearbeitet 16.06.2026 23:11:49
Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathna...
CVE-2009-3621
- EPSS 0.99%
- Veröffentlicht 22.10.2009 16:00:00
- Zuletzt bearbeitet 16.06.2026 23:12:02
net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing ...
CVE-2009-2848
- EPSS 0.52%
- Veröffentlicht 18.08.2009 21:00:00
- Zuletzt bearbeitet 16.06.2026 23:10:20
The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone ...
CVE-2009-2416
- EPSS 1.81%
- Veröffentlicht 11.08.2009 18:30:00
- Zuletzt bearbeitet 16.06.2026 23:09:24
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...
CVE-2009-1630
- EPSS 0.49%
- Veröffentlicht 14.05.2009 17:30:00
- Zuletzt bearbeitet 16.06.2026 23:07:40
The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass pe...
CVE-2009-1072
- EPSS 0.43%
- Veröffentlicht 25.03.2009 01:30:00
- Zuletzt bearbeitet 16.06.2026 23:06:26
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash o...
CVE-2009-0778
- EPSS 4.62%
- Veröffentlicht 12.03.2009 15:20:49
- Zuletzt bearbeitet 16.06.2026 23:05:47
The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of a...
CVE-2009-0034
- EPSS 0.41%
- Veröffentlicht 30.01.2009 19:30:00
- Zuletzt bearbeitet 16.06.2026 23:04:08
parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file...
CVE-2008-4279
- EPSS 0.39%
- Veröffentlicht 06.10.2008 19:54:36
- Zuletzt bearbeitet 16.06.2026 22:57:31
The CPU hardware emulation for 64-bit guest operating systems in VMware Workstation 6.0.x before 6.0.5 build 109488 and 5.x before 5.5.8 build 108000; Player 2.0.x before 2.0.5 build 109488 and 1.x before 1.0.8; Server 1.x before 1.0.7 build 108231; ...