Show filters
105 Total Results
Displaying 61-70 of 105
Sort by:
Attacker Value
Unknown

CVE-2013-2234

Disclosure Date: July 04, 2013 (last updated October 05, 2023)
The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key.c in the Linux kernel before 3.10 do not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify interface of an IPSec key_socket.
0
Attacker Value
Unknown

CVE-2013-2164

Disclosure Date: July 04, 2013 (last updated October 05, 2023)
The mmc_ioctl_cdrom_read_data function in drivers/cdrom/cdrom.c in the Linux kernel through 3.10 allows local users to obtain sensitive information from kernel memory via a read operation on a malfunctioning CD-ROM drive.
0
Attacker Value
Unknown

CVE-2013-2237

Disclosure Date: July 04, 2013 (last updated October 05, 2023)
The key_notify_policy_flush function in net/key/af_key.c in the Linux kernel before 3.9 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify_policy interface of an IPSec key_socket.
0
Attacker Value
Unknown

CVE-2013-1959

Disclosure Date: May 03, 2013 (last updated October 05, 2023)
kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_map and gid_map files, which allows local users to gain privileges by opening a file within an unprivileged process and then modifying the file within a privileged process.
0
Attacker Value
Unknown

CVE-2013-3302

Disclosure Date: April 29, 2013 (last updated October 05, 2023)
Race condition in the smb_send_rqst function in fs/cifs/transport.c in the Linux kernel before 3.7.2 allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors involving a reconnection event.
0
Attacker Value
Unknown

CVE-2013-1928

Disclosure Date: April 29, 2013 (last updated October 05, 2023)
The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel before 3.6.5 on unspecified architectures lacks a certain error check, which might allow local users to obtain sensitive information from kernel stack memory via a crafted VIDEO_SET_SPU_PALETTE ioctl call on a /dev/dvb device.
0
Attacker Value
Unknown

CVE-2013-2015

Disclosure Date: April 29, 2013 (last updated October 05, 2023)
The ext4_orphan_del function in fs/ext4/namei.c in the Linux kernel before 3.7.3 does not properly handle orphan-list entries for non-journal filesystems, which allows physically proximate attackers to cause a denial of service (system hang) via a crafted filesystem on removable media, as demonstrated by the e2fsprogs tests/f_orphan_extents_inode/image.gz test.
0
Attacker Value
Unknown

CVE-2013-1858

Disclosure Date: April 05, 2013 (last updated October 05, 2023)
The clone system-call implementation in the Linux kernel before 3.8.3 does not properly handle a combination of the CLONE_NEWUSER and CLONE_FS flags, which allows local users to gain privileges by calling chroot and leveraging the sharing of the / directory between a parent process and a child process.
0
Attacker Value
Unknown

CVE-2012-6542

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel before 3.6 has an incorrect return value in certain circumstances, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that leverages an uninitialized pointer argument.
0
Attacker Value
Unknown

CVE-2012-6538

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorrect C library function for copying a string, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability.
0