Show filters
109 Total Results
Displaying 101-109 of 109
Sort by:
Attacker Value
Unknown
CVE-2009-1601
Disclosure Date: May 11, 2009 (last updated October 04, 2023)
The Ubuntu clamav-milter.init script in clamav-milter before 0.95.1+dfsg-1ubuntu1.2 in Ubuntu 9.04 sets the ownership of the current working directory to the clamav account, which might allow local users to bypass intended access restrictions via read or write operations involving this directory.
0
Attacker Value
Unknown
CVE-2009-1191
Disclosure Date: April 23, 2009 (last updated October 04, 2023)
mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
0
Attacker Value
Unknown
CVE-2009-0946
Disclosure Date: April 17, 2009 (last updated October 04, 2023)
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
0
Attacker Value
Unknown
CVE-2009-1242
Disclosure Date: April 06, 2009 (last updated October 04, 2023)
The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode enable") bit in the Extended Feature Enable Register (EFER) model-specific register, which is specific to the x86_64 platform.
0
Attacker Value
Unknown
CVE-2009-1072
Disclosure Date: March 25, 2009 (last updated October 04, 2023)
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
0
Attacker Value
Unknown
CVE-2008-4577
Disclosure Date: October 15, 2008 (last updated January 21, 2024)
The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
0
Attacker Value
Unknown
CVE-2008-4098
Disclosure Date: September 18, 2008 (last updated October 04, 2023)
MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.
0
Attacker Value
Unknown
CVE-2008-3529
Disclosure Date: September 12, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.
0
Attacker Value
Unknown
CVE-2008-2009
Disclosure Date: May 16, 2008 (last updated October 04, 2023)
Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree function.
0