CVE-2009-2692
- EPSS 14.61%
- Veröffentlicht 14.08.2009 15:16:27
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using ...
CVE-2009-2416
- EPSS 0.19%
- Veröffentlicht 11.08.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...
- EPSS 0.36%
- Veröffentlicht 06.08.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop a...
CVE-2009-2687
- EPSS 11.71%
- Veröffentlicht 05.08.2009 19:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.
CVE-2009-1721
- EPSS 25.35%
- Veröffentlicht 31.07.2009 19:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of a...
CVE-2009-2408
- EPSS 2.02%
- Veröffentlicht 30.07.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certif...
CVE-2009-1895
- EPSS 0.06%
- Veröffentlicht 16.07.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to l...
CVE-2009-1891
- EPSS 18.85%
- Veröffentlicht 10.07.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
CVE-2009-1890
- EPSS 21.56%
- Veröffentlicht 05.07.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which al...
CVE-2009-2287
- EPSS 0.06%
- Veröffentlicht 01.07.2009 13:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, does not validate the page table root in a KVM_SET_SREGS call, which allows local users to cause a denial of service (crash or hang)...