CVE-2010-0629
- EPSS 2.28%
- Published 07.04.2010 15:30:00
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an inva...
- EPSS 3.8%
- Published 06.04.2010 16:30:00
- Last modified 11.04.2025 00:51:21
The ip_evictor function in ip_fragment.c in libnids before 1.24, as used in dsniff and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via crafted fragmented packets.
CVE-2010-0050
- EPSS 45.13%
- Published 15.03.2010 14:15:32
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improperly nested tags.
CVE-2010-0302
- EPSS 5.29%
- Published 05.03.2010 19:30:00
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denia...
CVE-2010-0434
- EPSS 2.55%
- Published 05.03.2010 19:30:00
- Last modified 11.04.2025 00:51:21
The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, wh...
CVE-2010-0205
- EPSS 8.13%
- Published 03.03.2010 19:30:00
- Last modified 11.04.2025 00:51:21
The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which...
CVE-2010-0013
- EPSS 12.31%
- Published 09.01.2010 18:30:01
- Last modified 09.04.2025 00:30:58
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) requ...
CVE-2009-4135
- EPSS 0.03%
- Published 11.12.2009 16:30:00
- Last modified 09.04.2025 00:30:58
The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.
CVE-2009-3553
- EPSS 9.85%
- Published 20.11.2009 02:30:00
- Last modified 09.04.2025 00:30:58
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash ...
CVE-2009-2816
- EPSS 2.15%
- Published 13.11.2009 15:30:00
- Last modified 09.04.2025 00:30:58
The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight,...