CVE-2009-1072
- EPSS 0.8%
- Veröffentlicht 25.03.2009 01:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash o...
CVE-2009-0586
- EPSS 3.15%
- Veröffentlicht 14.03.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/gstvorbistag.c) in vorbistag in gst-plugins-base (aka gstreamer-plugins-base) before 0.10.23 in GStreamer allows context-dependent attackers to execute arbitrary code via ...
CVE-2009-0834
- EPSS 0.06%
- Veröffentlicht 06.03.2009 11:30:02
- Zuletzt bearbeitet 09.04.2025 00:30:58
The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass...
CVE-2009-0385
- EPSS 11.55%
- Veröffentlicht 02.02.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL p...
CVE-2009-0322
- EPSS 0.05%
- Veröffentlicht 28.01.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size...
CVE-2008-5983
- EPSS 0.12%
- Veröffentlicht 28.01.2009 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local us...
CVE-2009-0269
- EPSS 0.08%
- Veröffentlicht 26.01.2009 15:30:04
- Zuletzt bearbeitet 09.04.2025 00:30:58
fs/ecryptfs/inode.c in the eCryptfs subsystem in the Linux kernel before 2.6.28.1 allows local users to cause a denial of service (fault or memory corruption), or possibly have unspecified other impact, via a readlink call that results in an error, l...
CVE-2008-4539
- EPSS 0.05%
- Veröffentlicht 29.12.2008 15:24:23
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap over...
- EPSS 3.55%
- Veröffentlicht 17.12.2008 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via ve...
- EPSS 4.54%
- Veröffentlicht 17.12.2008 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service via vectors that trigger an assertion failure.