Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 53 096

Количество 53 096

redhat логотип

CVE-2010-4668

больше 15 лет назад

The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.37-rc7 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device, related to an unaligned map. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4163.

CVSS2: 4.7
EPSS: Низкий
redhat логотип

CVE-2010-4666

больше 15 лет назад

Buffer overflow in libarchive 3.0 pre-release code allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CAB file, which is not properly handled during the reading of Huffman code data within LZX compressed data.

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2010-4665

около 16 лет назад

Integer overflow in the ReadDirectory function in tiffdump.c in tiffdump in LibTIFF before 3.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF file containing a directory data structure with many directory entries.

CVSS2: 3.7
EPSS: Низкий
redhat логотип

CVE-2010-4664

около 16 лет назад

In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.

CVSS2: 6.5
EPSS: Низкий
redhat логотип

CVE-2010-4661

больше 15 лет назад

udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.

CVSS2: 4.6
EPSS: Низкий
redhat логотип

CVE-2010-4657

почти 16 лет назад

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2010-4656

почти 16 лет назад

The iowarrior_write function in drivers/usb/misc/iowarrior.c in the Linux kernel before 2.6.37 does not properly allocate memory, which might allow local users to trigger a heap-based buffer overflow, and consequently cause a denial of service or gain privileges, via a long report.

CVSS2: 6.2
EPSS: Низкий
redhat логотип

CVE-2010-4655

почти 16 лет назад

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool ioctl call.

CVSS2: 1.2
EPSS: Низкий
redhat логотип

CVE-2010-4654

больше 16 лет назад

poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2010-4653

больше 16 лет назад

An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2010-4651

больше 15 лет назад

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2010-4650

больше 15 лет назад

Buffer overflow in the fuse_do_ioctl function in fs/fuse/file.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service or possibly have unspecified other impact by leveraging the ability to operate a CUSE server.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2010-4649

больше 15 лет назад

Integer overflow in the ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large value of a certain structure member.

CVSS2: 6.9
EPSS: Низкий
redhat логотип

CVE-2010-4648

больше 15 лет назад

The orinoco_ioctl_set_auth function in drivers/net/wireless/orinoco/wext.c in the Linux kernel before 2.6.37 does not properly implement a TKIP protection mechanism, which makes it easier for remote attackers to obtain access to a Wi-Fi network by reading Wi-Fi frames.

CVSS2: 3.3
EPSS: Низкий
redhat логотип

CVE-2010-4647

больше 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2010-4645

больше 15 лет назад

strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation, which is not properly handled in x87 FPU registers, as demonstrated using 2.2250738585072011e-308.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2010-4644

почти 16 лет назад

Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2010-4643

больше 15 лет назад

Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.

CVSS2: 6.8
EPSS: Средний
redhat логотип

CVE-2010-4578

больше 15 лет назад

Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers."

CVSS2: 3.7
EPSS: Низкий
redhat логотип

CVE-2010-4577

больше 15 лет назад

The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted local font, related to "Type Confusion."

CVSS2: 3.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2010-4668

The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.37-rc7 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device, related to an unaligned map. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4163.

CVSS2: 4.7
0%
Низкий
больше 15 лет назад
redhat логотип
CVE-2010-4666

Buffer overflow in libarchive 3.0 pre-release code allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CAB file, which is not properly handled during the reading of Huffman code data within LZX compressed data.

CVSS2: 5.1
2%
Низкий
больше 15 лет назад
redhat логотип
CVE-2010-4665

Integer overflow in the ReadDirectory function in tiffdump.c in tiffdump in LibTIFF before 3.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF file containing a directory data structure with many directory entries.

CVSS2: 3.7
3%
Низкий
около 16 лет назад
redhat логотип
CVE-2010-4664

In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.

CVSS2: 6.5
1%
Низкий
около 16 лет назад
redhat логотип
CVE-2010-4661

udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.

CVSS2: 4.6
0%
Низкий
больше 15 лет назад
redhat логотип
CVE-2010-4657

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

CVSS2: 4.3
2%
Низкий
почти 16 лет назад
redhat логотип
CVE-2010-4656

The iowarrior_write function in drivers/usb/misc/iowarrior.c in the Linux kernel before 2.6.37 does not properly allocate memory, which might allow local users to trigger a heap-based buffer overflow, and consequently cause a denial of service or gain privileges, via a long report.

CVSS2: 6.2
0%
Низкий
почти 16 лет назад
redhat логотип
CVE-2010-4655

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool ioctl call.

CVSS2: 1.2
0%
Низкий
почти 16 лет назад
redhat логотип
CVE-2010-4654

poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.

CVSS2: 6.8
1%
Низкий
больше 16 лет назад
redhat логотип
CVE-2010-4653

An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.

CVSS2: 5.1
2%
Низкий
больше 16 лет назад
redhat логотип
CVE-2010-4651

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

CVSS2: 2.1
5%
Низкий
больше 15 лет назад
redhat логотип
CVE-2010-4650

Buffer overflow in the fuse_do_ioctl function in fs/fuse/file.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service or possibly have unspecified other impact by leveraging the ability to operate a CUSE server.

CVSS2: 4
0%
Низкий
больше 15 лет назад
redhat логотип
CVE-2010-4649

Integer overflow in the ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large value of a certain structure member.

CVSS2: 6.9
0%
Низкий
больше 15 лет назад
redhat логотип
CVE-2010-4648

The orinoco_ioctl_set_auth function in drivers/net/wireless/orinoco/wext.c in the Linux kernel before 2.6.37 does not properly implement a TKIP protection mechanism, which makes it easier for remote attackers to obtain access to a Wi-Fi network by reading Wi-Fi frames.

CVSS2: 3.3
2%
Низкий
больше 15 лет назад
redhat логотип
CVE-2010-4647

Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp.

CVSS2: 2.6
5%
Низкий
больше 15 лет назад
redhat логотип
CVE-2010-4645

strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation, which is not properly handled in x87 FPU registers, as demonstrated using 2.2250738585072011e-308.

CVSS2: 5
15%
Средний
больше 15 лет назад
redhat логотип
CVE-2010-4644

Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.

CVSS2: 4
4%
Низкий
почти 16 лет назад
redhat логотип
CVE-2010-4643

Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.

CVSS2: 6.8
10%
Средний
больше 15 лет назад
redhat логотип
CVE-2010-4578

Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers."

CVSS2: 3.7
2%
Низкий
больше 15 лет назад
redhat логотип
CVE-2010-4577

The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted local font, related to "Type Confusion."

CVSS2: 3.7
2%
Низкий
больше 15 лет назад

Уязвимостей на страницу