CVE-2010-3069
- EPSS 16.56%
- Veröffentlicht 15.09.2010 18:00:44
- Zuletzt bearbeitet 29.04.2026 01:13:23
Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file ...
CVE-2010-1781
- EPSS 8%
- Veröffentlicht 09.09.2010 22:00:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Double free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the rendering of an inline element.
CVE-2010-1812
- EPSS 5.51%
- Veröffentlicht 09.09.2010 22:00:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving selectio...
CVE-2010-1814
- EPSS 4.6%
- Veröffentlicht 09.09.2010 22:00:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving form menus.
CVE-2010-1815
- EPSS 5.51%
- Veröffentlicht 09.09.2010 22:00:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving scrollba...
CVE-2010-2960
- EPSS 0.1%
- Veröffentlicht 08.09.2010 20:00:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL pointer dereference and system ...
CVE-2010-2955
- EPSS 0.09%
- Veröffentlicht 08.09.2010 20:00:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by-one error in the ioctl_standa...
CVE-2009-4895
- EPSS 0.06%
- Veröffentlicht 08.09.2010 20:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via unknown v...
CVE-2010-2066
- EPSS 0.1%
- Veröffentlicht 08.09.2010 20:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor.
- EPSS 2.31%
- Veröffentlicht 08.09.2010 20:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointe...