CVE-2009-4484
- EPSS 74.61%
- Veröffentlicht 30.12.2009 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, ...
CVE-2009-4135
- EPSS 0.03%
- Veröffentlicht 11.12.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.
CVE-2009-3080
- EPSS 0.07%
- Veröffentlicht 20.11.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.
CVE-2009-3553
- EPSS 9.85%
- Veröffentlicht 20.11.2009 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash ...
CVE-2009-3939
- EPSS 0.04%
- Veröffentlicht 16.11.2009 19:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
CVE-2009-3555
- EPSS 3.08%
- Veröffentlicht 09.11.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Secu...
CVE-2009-3725
- EPSS 0.05%
- Veröffentlicht 06.11.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restric...
- EPSS 2.41%
- Veröffentlicht 04.11.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathna...
CVE-2009-3620
- EPSS 0.07%
- Veröffentlicht 22.10.2009 16:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash...
CVE-2009-3621
- EPSS 0.04%
- Veröffentlicht 22.10.2009 16:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing ...