CVE-2007-6716
- EPSS 0.52%
- Veröffentlicht 04.09.2008 17:41:00
- Zuletzt bearbeitet 16.06.2026 22:48:38
fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.
CVE-2008-3281
- EPSS 2.51%
- Veröffentlicht 27.08.2008 20:41:00
- Zuletzt bearbeitet 16.06.2026 22:55:31
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
CVE-2008-3275
- EPSS 0.51%
- Veröffentlicht 12.08.2008 23:41:00
- Zuletzt bearbeitet 16.06.2026 22:55:31
The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denia...
CVE-2008-1945
- EPSS 0.47%
- Veröffentlicht 08.08.2008 19:41:00
- Zuletzt bearbeitet 16.06.2026 22:52:48
QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different for...
CVE-2008-3534
- EPSS 0.53%
- Veröffentlicht 08.08.2008 19:41:00
- Zuletzt bearbeitet 16.06.2026 22:56:00
The shmem_delete_inode function in mm/shmem.c in the tmpfs implementation in the Linux kernel before 2.6.26.1 allows local users to cause a denial of service (system crash) via a certain sequence of file create, remove, and overwrite operations, as d...
CVE-2008-3535
- EPSS 0.53%
- Veröffentlicht 08.08.2008 19:41:00
- Zuletzt bearbeitet 16.06.2026 22:56:00
Off-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-rc2 allows local users to cause a denial of service (system crash) via a certain sequence of file I/O operations with readv and writev, as demonstrate...
CVE-2008-3272
- EPSS 0.42%
- Veröffentlicht 08.08.2008 18:41:00
- Zuletzt bearbeitet 16.06.2026 22:55:30
The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain da...
CVE-2008-3142
- EPSS 4.49%
- Veröffentlicht 01.08.2008 14:41:00
- Zuletzt bearbeitet 16.06.2026 22:55:13
Multiple buffer overflows in Python 2.5.2 and earlier on 32bit platforms allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a long string that leads to incorrect memory allocation during Unicod...
- EPSS 1.06%
- Veröffentlicht 25.07.2008 16:41:00
- Zuletzt bearbeitet 16.06.2026 22:55:36
Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.
CVE-2008-2931
- EPSS 0.38%
- Veröffentlicht 09.07.2008 18:41:00
- Zuletzt bearbeitet 16.06.2026 22:54:45
The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of ...