CVE-2010-3432
- EPSS 4.32%
- Veröffentlicht 22.11.2010 13:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs extraneous initializations of packet data structures, which allows remote attackers to cause a denial of service (panic) via a certain sequence of SCTP ...
CVE-2010-4008
- EPSS 0.76%
- Veröffentlicht 17.11.2010 01:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to ca...
CVE-2010-3870
- EPSS 0.71%
- Veröffentlicht 12.11.2010 21:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protec...
- EPSS 3.61%
- Veröffentlicht 09.11.2010 01:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.
CVE-2010-3709
- EPSS 6.08%
- Veröffentlicht 09.11.2010 01:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.
CVE-2010-3702
- EPSS 3.86%
- Veröffentlicht 05.11.2010 18:00:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unkn...
CVE-2010-2941
- EPSS 26.54%
- Veröffentlicht 05.11.2010 17:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbi...
CVE-2010-3437
- EPSS 1.83%
- Veröffentlicht 04.10.2010 21:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dere...
CVE-2010-3442
- EPSS 0.18%
- Veröffentlicht 04.10.2010 21:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel before 2.6.36-rc5-next-20100929 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a...
CVE-2010-3079
- EPSS 0.12%
- Veröffentlicht 30.09.2010 15:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and llseek operations, which allows local users to cause a denial of service (NULL pointer dereference a...