Show filters
159 Total Results
Displaying 31-40 of 159
Sort by:
Attacker Value
Unknown
CVE-2009-4141
Disclosure Date: January 19, 2010 (last updated October 04, 2023)
Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privileges via vectors that include enabling O_ASYNC (aka FASYNC or FIOASYNC) on a locked file, and then closing this file.
0
Attacker Value
Unknown
CVE-2010-0007
Disclosure Date: January 19, 2010 (last updated October 04, 2023)
net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.
0
Attacker Value
Unknown
CVE-2009-4138
Disclosure Date: December 16, 2009 (last updated October 04, 2023)
drivers/firewire/ohci.c in the Linux kernel before 2.6.32-git9, when packet-per-buffer mode is used, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unknown other impact via an unspecified ioctl associated with receiving an ISO packet that contains zero in the payload-length field.
0
Attacker Value
Unknown
CVE-2009-4131
Disclosure Date: December 13, 2009 (last updated October 04, 2023)
The EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementation in the ext4 filesystem in the Linux kernel before 2.6.32-git6 allows local users to overwrite arbitrary files via a crafted request, related to insufficient checks for file permissions.
0
Attacker Value
Unknown
CVE-2009-4308
Disclosure Date: December 13, 2009 (last updated October 04, 2023)
The ext4_decode_error function in fs/ext4/super.c in the ext4 filesystem in the Linux kernel before 2.6.32 allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference), and possibly have unspecified other impact, via a crafted read-only filesystem that lacks a journal.
0
Attacker Value
Unknown
CVE-2009-4307
Disclosure Date: December 13, 2009 (last updated October 04, 2023)
The ext4_fill_flex_info function in fs/ext4/super.c in the Linux kernel before 2.6.32-git6 allows user-assisted remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ext4 filesystem containing a super block with a large FLEX_BG group size (aka s_log_groups_per_flex value).
0
Attacker Value
Unknown
CVE-2009-4306
Disclosure Date: December 13, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementation in the ext4 filesystem in the Linux kernel 2.6.32-git6 and earlier allows local users to cause a denial of service (filesystem corruption) via unknown vectors, a different vulnerability than CVE-2009-4131.
0
Attacker Value
Unknown
CVE-2009-4026
Disclosure Date: December 02, 2009 (last updated October 04, 2023)
The mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (panic) via a crafted Delete Block ACK (aka DELBA) packet, related to an erroneous "code shuffling patch."
0
Attacker Value
Unknown
CVE-2009-4027
Disclosure Date: December 02, 2009 (last updated October 04, 2023)
Race condition in the mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (system crash) via a Delete Block ACK (aka DELBA) packet that triggers a certain state change in the absence of an aggregation session.
0
Attacker Value
Unknown
CVE-2009-4021
Disclosure Date: November 25, 2009 (last updated October 04, 2023)
The fuse_direct_io function in fs/fuse/file.c in the fuse subsystem in the Linux kernel before 2.6.32-rc7 might allow attackers to cause a denial of service (invalid pointer dereference and OOPS) via vectors possibly related to a memory-consumption attack.
0