Show filters
100 Total Results
Displaying 51-60 of 100
Sort by:
Attacker Value
Unknown

CVE-2009-1387

Disclosure Date: June 04, 2009 (last updated February 08, 2024)
The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a "fragment bug."
0
Attacker Value
Unknown

CVE-2009-1386

Disclosure Date: June 04, 2009 (last updated February 08, 2024)
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.
0
Attacker Value
Unknown

CVE-2009-1633

Disclosure Date: May 28, 2009 (last updated October 04, 2023)
Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode string area alignment in fs/cifs/sess.c; or (2) long Unicode characters, related to fs/cifs/cifssmb.c and the cifs_readdir function in fs/cifs/readdir.c.
0
Attacker Value
Unknown

CVE-2009-1378

Disclosure Date: May 19, 2009 (last updated February 08, 2024)
Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or (2) have sequence numbers much greater than current sequence numbers, aka "DTLS fragment handling memory leak."
0
Attacker Value
Unknown

CVE-2009-1630

Disclosure Date: May 14, 2009 (last updated October 04, 2023)
The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.
0
Attacker Value
Unknown

CVE-2009-1191

Disclosure Date: April 23, 2009 (last updated October 04, 2023)
mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
0
Attacker Value
Unknown

CVE-2009-1185

Disclosure Date: April 17, 2009 (last updated October 04, 2023)
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
0
Attacker Value
Unknown

CVE-2009-1186

Disclosure Date: April 17, 2009 (last updated October 04, 2023)
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
0
Attacker Value
Unknown

CVE-2009-0946

Disclosure Date: April 17, 2009 (last updated October 04, 2023)
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
0
Attacker Value
Unknown

CVE-2009-0846

Disclosure Date: April 09, 2009 (last updated February 09, 2024)
The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.
0