- EPSS 0.1%
- Published 29.12.2010 18:00:02
- Last modified 11.04.2025 00:51:21
Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.36.2 on 64-bit platforms might allow local users to cause a denial ...
CVE-2010-4577
- EPSS 4.27%
- Published 22.12.2010 01:00:03
- Last modified 11.04.2025 00:51:21
The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS...
CVE-2010-4157
- EPSS 0.11%
- Published 10.12.2010 19:00:05
- Last modified 11.04.2025 00:51:21
Integer overflow in the ioc_general function in drivers/scsi/gdth.c in the Linux kernel before 2.6.36.1 on 64-bit platforms allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large argu...
CVE-2010-4494
- EPSS 1.62%
- Published 07.12.2010 21:00:09
- Last modified 11.04.2025 00:51:21
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath...
CVE-2010-4180
- EPSS 5.99%
- Published 06.12.2010 21:05:48
- Last modified 11.04.2025 00:51:21
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an uninte...
CVE-2010-4249
- EPSS 0.1%
- Published 29.11.2010 16:00:04
- Last modified 11.04.2025 00:51:21
The wait_for_unix_gc function in net/unix/garbage.c in the Linux kernel before 2.6.37-rc3-next-20101125 does not properly select times for garbage collection of inflight sockets, which allows local users to cause a denial of service (system hang) via...
CVE-2010-3705
- EPSS 1.22%
- Published 26.11.2010 20:00:02
- Last modified 11.04.2025 00:51:21
The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denial of service (memory corruption and panic) via a cr...
CVE-2010-3698
- EPSS 0.1%
- Published 26.11.2010 19:00:07
- Last modified 11.04.2025 00:51:21
The KVM implementation in the Linux kernel before 2.6.36 does not properly reload the FS and GS segment registers, which allows host OS users to cause a denial of service (host OS crash) via a KVM_RUN ioctl call in conjunction with a modified Local D...
CVE-2010-2962
- EPSS 0.12%
- Published 26.11.2010 19:00:06
- Last modified 11.04.2025 00:51:21
drivers/gpu/drm/i915/i915_gem.c in the Graphics Execution Manager (GEM) in the Intel i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.36 does not properly validate pointers to blocks of memory, which allows l...
CVE-2010-2963
- EPSS 0.05%
- Published 26.11.2010 19:00:06
- Last modified 11.04.2025 00:51:21
drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local users to write to arbitrary kerne...