CVE-2011-1593
- EPSS 0.04%
- Veröffentlicht 03.05.2011 20:55:08
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple integer overflows in the next_pidmap function in kernel/pid.c in the Linux kernel before 2.6.38.4 allow local users to cause a denial of service (system crash) via a crafted (1) getdents or (2) readdir system call.
CVE-2011-0463
- EPSS 0.09%
- Veröffentlicht 10.04.2011 02:51:19
- Zuletzt bearbeitet 29.04.2026 01:13:23
The ocfs2_prepare_page_for_write function in fs/ocfs2/aops.c in the Oracle Cluster File System 2 (OCFS2) subsystem in the Linux kernel before 2.6.39-rc1 does not properly handle holes that cross page boundaries, which allows local users to obtain pot...
CVE-2011-0997
- EPSS 73.5%
- Veröffentlicht 08.04.2011 15:17:27
- Zuletzt bearbeitet 29.04.2026 01:13:23
dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstra...
CVE-2011-1400
- EPSS 2.1%
- Veröffentlicht 25.03.2011 19:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating systems lists certain program...
CVE-2011-0695
- EPSS 0.44%
- Veröffentlicht 15.03.2011 17:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in Linux kernel 2.6.x allows remote attackers to cause a denial of service (panic) by sending an InfiniBand request while other request handlers a...
- EPSS 45.28%
- Veröffentlicht 02.03.2011 20:00:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions...
CVE-2011-1012
- EPSS 0.03%
- Veröffentlicht 01.03.2011 23:00:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
The ldm_parse_vmdb function in fs/partitions/ldm.c in the Linux kernel before 2.6.38-rc6-git6 does not validate the VBLK size value in the VMDB structure in an LDM partition table, which allows local users to cause a denial of service (divide-by-zero...
CVE-2011-1017
- EPSS 0.06%
- Veröffentlicht 01.03.2011 23:00:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2.6.37.2 and earlier might allow local users to gain privileges or obtain sensitive information via a crafted LDM partition table.
CVE-2011-0725
- EPSS 0.11%
- Veröffentlicht 23.02.2011 19:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Absolute path traversal vulnerability in the org.debian.apt.UpdateCachePartially method in worker.py in Aptdaemon 0.40 in Ubuntu 10.10 and 11.04 allows local users to read arbitrary files via a full pathname in the sources_list argument, related to t...
- EPSS 68.13%
- Veröffentlicht 22.02.2011 19:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353. NOTE: this vulnerability exists because of an incorrect f...