Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2014-2323

Disclosure Date: March 14, 2014 (last updated November 25, 2024)
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.
Attacker Value
Unknown

CVE-2014-2324

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
0
Attacker Value
Unknown

CVE-2013-3301

Disclosure Date: April 29, 2013 (last updated February 03, 2024)
The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.
0
Attacker Value
Unknown

CVE-2012-0879

Disclosure Date: May 17, 2012 (last updated October 04, 2023)
The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context.
Attacker Value
Unknown

CVE-2010-3881

Disclosure Date: December 23, 2010 (last updated October 04, 2023)
arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.
0
Attacker Value
Unknown

CVE-2010-2495

Disclosure Date: September 08, 2010 (last updated October 04, 2023)
The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors related to a routing change.
0
Attacker Value
Unknown

CVE-2010-2798

Disclosure Date: September 08, 2010 (last updated October 04, 2023)
The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by renaming a file in a GFS2 filesystem, related to the gfs2_rename function in fs/gfs2/ops_inode.c.
Attacker Value
Unknown

CVE-2010-2066

Disclosure Date: September 08, 2010 (last updated October 04, 2023)
The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor.