CVE-2009-1573
- EPSS 0.46%
- Veröffentlicht 06.05.2009 17:30:09
- Zuletzt bearbeitet 16.06.2026 23:07:33
xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.
CVE-2009-1185
- EPSS 81.53%
- Veröffentlicht 17.04.2009 14:30:00
- Zuletzt bearbeitet 16.06.2026 23:06:41
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
CVE-2009-1186
- EPSS 0.54%
- Veröffentlicht 17.04.2009 14:30:00
- Zuletzt bearbeitet 16.06.2026 23:06:41
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
CVE-2009-0946
- EPSS 8.54%
- Veröffentlicht 17.04.2009 00:30:00
- Zuletzt bearbeitet 16.06.2026 23:06:10
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
CVE-2009-1270
- EPSS 5.07%
- Veröffentlicht 08.04.2009 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:06:54
libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.
CVE-2009-1242
- EPSS 0.47%
- Veröffentlicht 06.04.2009 14:30:00
- Zuletzt bearbeitet 16.06.2026 23:06:50
The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode e...
CVE-2009-1073
- EPSS 0.93%
- Veröffentlicht 31.03.2009 18:24:45
- Zuletzt bearbeitet 16.06.2026 23:06:26
nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.
CVE-2009-0115
- EPSS 0.49%
- Veröffentlicht 30.03.2009 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:04:17
The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket ...
- EPSS 6.19%
- Veröffentlicht 27.03.2009 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:05:22
The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid ...
CVE-2009-1151
- EPSS 95.44%
- Veröffentlicht 26.03.2009 14:30:00
- Zuletzt bearbeitet 16.06.2026 23:06:36
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.