Show filters
209 Total Results
Displaying 171-180 of 209
Sort by:
Attacker Value
Unknown
CVE-2009-0834
Disclosure Date: March 06, 2009 (last updated October 04, 2023)
The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.
0
Attacker Value
Unknown
CVE-2009-0040
Disclosure Date: February 22, 2009 (last updated February 09, 2024)
The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.
0
Attacker Value
Unknown
CVE-2008-5021
Disclosure Date: November 13, 2008 (last updated February 03, 2024)
nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory.
0
Attacker Value
Unknown
CVE-2008-4989
Disclosure Date: November 13, 2008 (last updated February 09, 2024)
The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers to insert a spoofed certificate for any Distinguished Name (DN).
0
Attacker Value
Unknown
CVE-2007-6716
Disclosure Date: September 04, 2008 (last updated October 04, 2023)
fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.
0
Attacker Value
Unknown
CVE-2008-3281
Disclosure Date: August 27, 2008 (last updated February 03, 2024)
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
0
Attacker Value
Unknown
CVE-2008-3275
Disclosure Date: August 12, 2008 (last updated October 04, 2023)
The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denial of service ("overflow" of the UBIFS orphan area) via a series of attempted file creations within deleted directories.
0
Attacker Value
Unknown
CVE-2008-1945
Disclosure Date: August 08, 2008 (last updated October 04, 2023)
QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different format, a related issue to CVE-2008-2004.
0
Attacker Value
Unknown
CVE-2008-3272
Disclosure Date: August 08, 2008 (last updated October 04, 2023)
The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain data to the caller, which allows local users to obtain sensitive information.
0
Attacker Value
Unknown
CVE-2008-2931
Disclosure Date: July 09, 2008 (last updated October 04, 2023)
The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of a mountpoint.
0