Show filters
251 Total Results
Displaying 11-20 of 251
Sort by:
Attacker Value
Unknown
CVE-2010-3904
Disclosure Date: December 06, 2010 (last updated June 28, 2024)
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
0
Attacker Value
Unknown
CVE-2010-4072
Disclosure Date: November 29, 2010 (last updated October 04, 2023)
The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl system call and the "old shm interface."
0
Attacker Value
Unknown
CVE-2010-3705
Disclosure Date: November 26, 2010 (last updated October 04, 2023)
The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denial of service (memory corruption and panic) via a crafted value in the last element of this array.
0
Attacker Value
Unknown
CVE-2010-2963
Disclosure Date: November 26, 2010 (last updated October 04, 2023)
drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local users to write to arbitrary kernel memory locations, and consequently gain privileges, via a VIDIOCSTUNER ioctl call on a /dev/video device, followed by a VIDIOCSMICROCODE ioctl call on this device.
0
Attacker Value
Unknown
CVE-2010-3432
Disclosure Date: November 22, 2010 (last updated October 04, 2023)
The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs extraneous initializations of packet data structures, which allows remote attackers to cause a denial of service (panic) via a certain sequence of SCTP traffic.
0
Attacker Value
Unknown
CVE-2010-3870
Disclosure Date: November 12, 2010 (last updated October 04, 2023)
The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.
0
Attacker Value
Unknown
CVE-2010-3709
Disclosure Date: November 09, 2010 (last updated October 04, 2023)
The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.
0
Attacker Value
Unknown
CVE-2010-3436
Disclosure Date: November 09, 2010 (last updated October 04, 2023)
fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.
0
Attacker Value
Unknown
CVE-2010-3702
Disclosure Date: November 05, 2010 (last updated October 04, 2023)
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
0
Attacker Value
Unknown
CVE-2010-2941
Disclosure Date: November 05, 2010 (last updated February 03, 2024)
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.
0