CVE-2010-1812
- EPSS 5.51%
- Veröffentlicht 09.09.2010 22:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving selectio...
CVE-2010-1814
- EPSS 4.6%
- Veröffentlicht 09.09.2010 22:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving form menus.
CVE-2010-1815
- EPSS 5.51%
- Veröffentlicht 09.09.2010 22:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving scrollba...
CVE-2010-2960
- EPSS 0.1%
- Veröffentlicht 08.09.2010 20:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL pointer dereference and system ...
CVE-2010-2955
- EPSS 0.1%
- Veröffentlicht 08.09.2010 20:00:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by-one error in the ioctl_standa...
CVE-2009-4895
- EPSS 0.06%
- Veröffentlicht 08.09.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via unknown v...
CVE-2010-2066
- EPSS 0.1%
- Veröffentlicht 08.09.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor.
- EPSS 1.5%
- Veröffentlicht 08.09.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointe...
CVE-2010-2524
- EPSS 0.09%
- Veröffentlicht 08.09.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace helper, which allows local user...
CVE-2010-2798
- EPSS 0.05%
- Veröffentlicht 08.09.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer derefe...