Show filters
110 Total Results
Displaying 61-70 of 110
Sort by:
Attacker Value
Unknown
CVE-2013-4125
Disclosure Date: July 15, 2013 (last updated October 05, 2023)
The fib6_add_rt2node function in net/ipv6/ip6_fib.c in the IPv6 stack in the Linux kernel through 3.10.1 does not properly handle Router Advertisement (RA) messages in certain circumstances involving three routes that initially qualified for membership in an ECMP route set until a change occurred for one of the first two routes, which allows remote attackers to cause a denial of service (system crash) via a crafted sequence of messages.
0
Attacker Value
Unknown
CVE-2013-2232
Disclosure Date: July 04, 2013 (last updated October 05, 2023)
The ip6_sk_dst_check function in net/ipv6/ip6_output.c in the Linux kernel before 3.10 allows local users to cause a denial of service (system crash) by using an AF_INET6 socket for a connection to an IPv4 interface.
0
Attacker Value
Unknown
CVE-2013-2206
Disclosure Date: July 04, 2013 (last updated October 05, 2023)
The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP implementation in the Linux kernel before 3.8.5 does not properly handle associations during the processing of a duplicate COOKIE ECHO chunk, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted SCTP traffic.
0
Attacker Value
Unknown
CVE-2013-2234
Disclosure Date: July 04, 2013 (last updated October 05, 2023)
The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key.c in the Linux kernel before 3.10 do not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify interface of an IPSec key_socket.
0
Attacker Value
Unknown
CVE-2013-2164
Disclosure Date: July 04, 2013 (last updated October 05, 2023)
The mmc_ioctl_cdrom_read_data function in drivers/cdrom/cdrom.c in the Linux kernel through 3.10 allows local users to obtain sensitive information from kernel memory via a read operation on a malfunctioning CD-ROM drive.
0
Attacker Value
Unknown
CVE-2013-2237
Disclosure Date: July 04, 2013 (last updated October 05, 2023)
The key_notify_policy_flush function in net/key/af_key.c in the Linux kernel before 3.9 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify_policy interface of an IPSec key_socket.
0
Attacker Value
Unknown
CVE-2013-1959
Disclosure Date: May 03, 2013 (last updated October 05, 2023)
kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_map and gid_map files, which allows local users to gain privileges by opening a file within an unprivileged process and then modifying the file within a privileged process.
0
Attacker Value
Unknown
CVE-2013-3302
Disclosure Date: April 29, 2013 (last updated October 05, 2023)
Race condition in the smb_send_rqst function in fs/cifs/transport.c in the Linux kernel before 3.7.2 allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors involving a reconnection event.
0
Attacker Value
Unknown
CVE-2013-1928
Disclosure Date: April 29, 2013 (last updated October 05, 2023)
The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel before 3.6.5 on unspecified architectures lacks a certain error check, which might allow local users to obtain sensitive information from kernel stack memory via a crafted VIDEO_SET_SPU_PALETTE ioctl call on a /dev/dvb device.
0
Attacker Value
Unknown
CVE-2013-2015
Disclosure Date: April 29, 2013 (last updated October 05, 2023)
The ext4_orphan_del function in fs/ext4/namei.c in the Linux kernel before 3.7.3 does not properly handle orphan-list entries for non-journal filesystems, which allows physically proximate attackers to cause a denial of service (system hang) via a crafted filesystem on removable media, as demonstrated by the e2fsprogs tests/f_orphan_extents_inode/image.gz test.
0