Show filters
425 Total Results
Displaying 371-380 of 425
Sort by:
Attacker Value
Unknown
CVE-2011-2022
Disclosure Date: May 09, 2011 (last updated October 04, 2023)
The agp_generic_remove_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 does not validate a certain start parameter, which allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_UNBIND agp_ioctl ioctl call, a different vulnerability than CVE-2011-1745.
0
Attacker Value
Unknown
CVE-2011-1746
Disclosure Date: May 09, 2011 (last updated October 04, 2023)
Multiple integer overflows in the (1) agp_allocate_memory and (2) agp_create_user_memory functions in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allow local users to trigger buffer overflows, and consequently cause a denial of service (system crash) or possibly have unspecified other impact, via vectors related to calls that specify a large number of memory pages.
0
Attacker Value
Unknown
CVE-2011-1745
Disclosure Date: May 09, 2011 (last updated October 04, 2023)
Integer overflow in the agp_generic_insert_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_BIND agp_ioctl ioctl call.
0
Attacker Value
Unknown
CVE-2011-1593
Disclosure Date: May 03, 2011 (last updated October 04, 2023)
Multiple integer overflows in the next_pidmap function in kernel/pid.c in the Linux kernel before 2.6.38.4 allow local users to cause a denial of service (system crash) via a crafted (1) getdents or (2) readdir system call.
0
Attacker Value
Unknown
CVE-2011-1163
Disclosure Date: April 10, 2011 (last updated October 04, 2023)
The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from kernel heap memory via vectors related to partition-table parsing.
0
Attacker Value
Unknown
CVE-2011-0695
Disclosure Date: March 15, 2011 (last updated October 04, 2023)
Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in Linux kernel 2.6.x allows remote attackers to cause a denial of service (panic) by sending an InfiniBand request while other request handlers are still running, which triggers an invalid pointer dereference.
0
Attacker Value
Unknown
CVE-2011-0711
Disclosure Date: March 01, 2011 (last updated October 04, 2023)
The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V1 ioctl call.
0
Attacker Value
Unknown
CVE-2010-4649
Disclosure Date: February 18, 2011 (last updated October 04, 2023)
Integer overflow in the ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large value of a certain structure member.
0
Attacker Value
Unknown
CVE-2011-1044
Disclosure Date: February 18, 2011 (last updated October 04, 2023)
The ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 does not initialize a certain response buffer, which allows local users to obtain potentially sensitive information from kernel memory via vectors that cause this buffer to be only partially filled, a different vulnerability than CVE-2010-4649.
0
Attacker Value
Unknown
CVE-2010-4008
Disclosure Date: December 07, 2010 (last updated October 04, 2023)
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
0