Show filters
508 Total Results
Displaying 381-390 of 508
Sort by:
Attacker Value
Unknown

CVE-2009-0949

Disclosure Date: June 09, 2009 (last updated February 09, 2024)
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.
Attacker Value
Unknown

CVE-2009-1961

Disclosure Date: June 08, 2009 (last updated February 16, 2024)
The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.
Attacker Value
Unknown

CVE-2009-1630

Disclosure Date: May 14, 2009 (last updated October 04, 2023)
The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.
0
Attacker Value
Unknown

CVE-2009-1185

Disclosure Date: April 17, 2009 (last updated October 04, 2023)
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
0
Attacker Value
Unknown

CVE-2009-1186

Disclosure Date: April 17, 2009 (last updated October 04, 2023)
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
0
Attacker Value
Unknown

CVE-2009-0946

Disclosure Date: April 17, 2009 (last updated October 04, 2023)
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
0
Attacker Value
Unknown

CVE-2009-1242

Disclosure Date: April 06, 2009 (last updated October 04, 2023)
The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode enable") bit in the Extended Feature Enable Register (EFER) model-specific register, which is specific to the x86_64 platform.
0
Attacker Value
Unknown

CVE-2009-1072

Disclosure Date: March 25, 2009 (last updated October 04, 2023)
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
0
Attacker Value
Unknown

CVE-2009-0834

Disclosure Date: March 06, 2009 (last updated October 04, 2023)
The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.
0
Attacker Value
Unknown

CVE-2009-0269

Disclosure Date: January 26, 2009 (last updated February 09, 2024)
fs/ecryptfs/inode.c in the eCryptfs subsystem in the Linux kernel before 2.6.28.1 allows local users to cause a denial of service (fault or memory corruption), or possibly have unspecified other impact, via a readlink call that results in an error, leading to use of a -1 return value as an array index.
0