CVE-2009-1573
- EPSS 0.07%
- Veröffentlicht 06.05.2009 17:30:09
- Zuletzt bearbeitet 09.04.2025 00:30:58
xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.
CVE-2009-1185
- EPSS 89.51%
- Veröffentlicht 17.04.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
CVE-2009-1186
- EPSS 0.09%
- Veröffentlicht 17.04.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
CVE-2009-0946
- EPSS 16.38%
- Veröffentlicht 17.04.2009 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
CVE-2009-1270
- EPSS 3.87%
- Veröffentlicht 08.04.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.
CVE-2009-1242
- EPSS 0.07%
- Veröffentlicht 06.04.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode e...
CVE-2009-1073
- EPSS 0.38%
- Veröffentlicht 31.03.2009 18:24:45
- Zuletzt bearbeitet 09.04.2025 00:30:58
nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.
CVE-2009-0115
- EPSS 0.08%
- Veröffentlicht 30.03.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket ...
- EPSS 10.02%
- Veröffentlicht 27.03.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid ...
CVE-2009-1151
- EPSS 92.96%
- Veröffentlicht 26.03.2009 14:30:00
- Zuletzt bearbeitet 22.10.2025 01:15:34
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.