CVE-2009-4013
- EPSS 0.84%
- Veröffentlicht 02.02.2010 16:30:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive information via vectors involving (1) control field ...
CVE-2009-4484
- EPSS 75.82%
- Veröffentlicht 30.12.2009 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, ...
CVE-2009-4135
- EPSS 0.03%
- Veröffentlicht 11.12.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.
CVE-2009-3080
- EPSS 0.07%
- Veröffentlicht 20.11.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.
CVE-2009-3553
- EPSS 9.85%
- Veröffentlicht 20.11.2009 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash ...
CVE-2009-3939
- EPSS 0.04%
- Veröffentlicht 16.11.2009 19:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
CVE-2009-3555
- EPSS 2.29%
- Veröffentlicht 09.11.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Secu...
CVE-2009-3725
- EPSS 0.04%
- Veröffentlicht 06.11.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restric...
- EPSS 3.05%
- Veröffentlicht 04.11.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathna...
CVE-2009-3620
- EPSS 0.07%
- Veröffentlicht 22.10.2009 16:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash...