CVE-2009-1603
- EPSS 1.05%
- Veröffentlicht 11.05.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of messages that were intended to b...
CVE-2009-1185
- EPSS 89.61%
- Veröffentlicht 17.04.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
CVE-2009-1186
- EPSS 0.09%
- Veröffentlicht 17.04.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
- EPSS 58.07%
- Veröffentlicht 09.04.2009 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code...
CVE-2009-1242
- EPSS 0.07%
- Veröffentlicht 06.04.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode e...
CVE-2008-6552
- EPSS 0.07%
- Veröffentlicht 30.03.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and ...
CVE-2009-0115
- EPSS 0.08%
- Veröffentlicht 30.03.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket ...
CVE-2009-0040
- EPSS 8.48%
- Veröffentlicht 22.02.2009 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a cr...
CVE-2009-0385
- EPSS 11.55%
- Veröffentlicht 02.02.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL p...
CVE-2009-0314
- EPSS 0.13%
- Veröffentlicht 28.01.2009 11:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Untrusted search path vulnerability in the Python module in gedit allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).