CVE-2009-1890
- EPSS 21.52%
- Veröffentlicht 05.07.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which al...
CVE-2009-2287
- EPSS 0.06%
- Veröffentlicht 01.07.2009 13:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, does not validate the page table root in a KVM_SET_SREGS call, which allows local users to cause a denial of service (crash or hang)...
CVE-2009-1888
- EPSS 5.39%
- Veröffentlicht 25.06.2009 01:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vecto...
CVE-2009-1699
- EPSS 5.63%
- Veröffentlicht 10.06.2009 18:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files ...
CVE-2009-0949
- EPSS 20.57%
- Veröffentlicht 09.06.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler re...
CVE-2009-1955
- EPSS 3.66%
- Veröffentlicht 08.06.2009 01:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via ...
CVE-2009-1956
- EPSS 4.27%
- Veröffentlicht 08.06.2009 01:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
CVE-2009-1961
- EPSS 0.13%
- Veröffentlicht 08.06.2009 01:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of ...
- EPSS 48.62%
- Veröffentlicht 04.06.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.
- EPSS 13.46%
- Veröffentlicht 04.06.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a...