Show filters
154 Total Results
Displaying 141-150 of 154
Sort by:
Attacker Value
Unknown
CVE-2010-3849
Disclosure Date: December 30, 2010 (last updated October 04, 2023)
The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a sendmsg call that specifies a NULL value for the remote address field.
0
Attacker Value
Unknown
CVE-2010-4072
Disclosure Date: November 29, 2010 (last updated October 04, 2023)
The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl system call and the "old shm interface."
0
Attacker Value
Unknown
CVE-2010-3442
Disclosure Date: October 04, 2010 (last updated October 04, 2023)
Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel before 2.6.36-rc5-next-20100929 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted (1) SNDRV_CTL_IOCTL_ELEM_ADD or (2) SNDRV_CTL_IOCTL_ELEM_REPLACE ioctl call.
0
Attacker Value
Unknown
CVE-2010-3437
Disclosure Date: October 04, 2010 (last updated October 04, 2023)
Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and system crash) via a crafted index value in a PKT_CTRL_CMD_STATUS ioctl call.
0
Attacker Value
Unknown
CVE-2010-3067
Disclosure Date: September 21, 2010 (last updated October 04, 2023)
Integer overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next-20100915 allows local users to cause a denial of service or possibly have unspecified other impact via crafted use of the io_submit system call.
0
Attacker Value
Unknown
CVE-2010-2226
Disclosure Date: September 03, 2010 (last updated October 04, 2023)
The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly check the file descriptors passed to the SWAPEXT ioctl, which allows local users to leverage write access and obtain read access by swapping one file into another file.
0
Attacker Value
Unknown
CVE-2009-2910
Disclosure Date: October 20, 2009 (last updated October 04, 2023)
arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 process to 64-bit mode.
0
Attacker Value
Unknown
CVE-2009-3612
Disclosure Date: October 19, 2009 (last updated November 08, 2023)
The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2005-4881.
0
Attacker Value
Unknown
CVE-2009-2903
Disclosure Date: September 15, 2009 (last updated October 04, 2023)
Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (memory consumption) via IP-DDP datagrams.
0
Attacker Value
Unknown
CVE-2008-5021
Disclosure Date: November 13, 2008 (last updated February 03, 2024)
nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory.
0