CVE-2009-1633
- EPSS 1.84%
- Veröffentlicht 28.05.2009 20:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to U...
- EPSS 13.25%
- Veröffentlicht 19.05.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or ...
CVE-2009-1630
- EPSS 0.11%
- Veröffentlicht 14.05.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass pe...
- EPSS 12%
- Veröffentlicht 23.04.2009 17:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
CVE-2009-1185
- EPSS 89.51%
- Veröffentlicht 17.04.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
CVE-2009-1186
- EPSS 0.09%
- Veröffentlicht 17.04.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
CVE-2009-0946
- EPSS 16.51%
- Veröffentlicht 17.04.2009 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
- EPSS 50.18%
- Veröffentlicht 09.04.2009 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code...
CVE-2009-1270
- EPSS 3.36%
- Veröffentlicht 08.04.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.
CVE-2009-1242
- EPSS 0.07%
- Veröffentlicht 06.04.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode e...