CVE-2009-3620
- EPSS 0.09%
- Veröffentlicht 22.10.2009 16:00:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash...
CVE-2009-3621
- EPSS 0.07%
- Veröffentlicht 22.10.2009 16:00:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing ...
CVE-2009-2910
- EPSS 0.05%
- Veröffentlicht 20.10.2009 17:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 p...
CVE-2009-3612
- EPSS 0.07%
- Veröffentlicht 19.10.2009 20:00:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensit...
CVE-2009-3231
- EPSS 4.96%
- Veröffentlicht 17.09.2009 10:30:01
- Zuletzt bearbeitet 23.04.2026 00:35:47
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
CVE-2009-2629
- EPSS 78.1%
- Veröffentlicht 15.09.2009 22:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
- EPSS 0.85%
- Veröffentlicht 14.09.2009 16:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle error...
CVE-2009-3094
- EPSS 2.83%
- Veröffentlicht 08.09.2009 18:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a mal...
- EPSS 3.04%
- Veröffentlicht 08.09.2009 18:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as...
CVE-2009-2698
- EPSS 26.12%
- Veröffentlicht 27.08.2009 17:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vecto...