Show filters
127 Total Results
Displaying 71-80 of 127
Sort by:
Attacker Value
Unknown

CVE-2013-2237

Disclosure Date: July 04, 2013 (last updated October 05, 2023)
The key_notify_policy_flush function in net/key/af_key.c in the Linux kernel before 3.9 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify_policy interface of an IPSec key_socket.
0
Attacker Value
Unknown

CVE-2011-4347

Disclosure Date: June 08, 2013 (last updated October 05, 2023)
The kvm_vm_ioctl_assign_device function in virt/kvm/assigned-dev.c in the KVM subsystem in the Linux kernel before 3.1.10 does not verify permission to access PCI configuration space and BAR resources, which allows host OS users to assign PCI devices and cause a denial of service (host OS crash) via a KVM_ASSIGN_PCI_DEVICE operation.
0
Attacker Value
Unknown

CVE-2013-1959

Disclosure Date: May 03, 2013 (last updated October 05, 2023)
kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_map and gid_map files, which allows local users to gain privileges by opening a file within an unprivileged process and then modifying the file within a privileged process.
0
Attacker Value
Unknown

CVE-2013-3302

Disclosure Date: April 29, 2013 (last updated October 05, 2023)
Race condition in the smb_send_rqst function in fs/cifs/transport.c in the Linux kernel before 3.7.2 allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors involving a reconnection event.
0
Attacker Value
Unknown

CVE-2013-1928

Disclosure Date: April 29, 2013 (last updated October 05, 2023)
The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel before 3.6.5 on unspecified architectures lacks a certain error check, which might allow local users to obtain sensitive information from kernel stack memory via a crafted VIDEO_SET_SPU_PALETTE ioctl call on a /dev/dvb device.
0
Attacker Value
Unknown

CVE-2013-2015

Disclosure Date: April 29, 2013 (last updated October 05, 2023)
The ext4_orphan_del function in fs/ext4/namei.c in the Linux kernel before 3.7.3 does not properly handle orphan-list entries for non-journal filesystems, which allows physically proximate attackers to cause a denial of service (system hang) via a crafted filesystem on removable media, as demonstrated by the e2fsprogs tests/f_orphan_extents_inode/image.gz test.
0
Attacker Value
Unknown

CVE-2013-1858

Disclosure Date: April 05, 2013 (last updated October 05, 2023)
The clone system-call implementation in the Linux kernel before 3.8.3 does not properly handle a combination of the CLONE_NEWUSER and CLONE_FS flags, which allows local users to gain privileges by calling chroot and leveraging the sharing of the / directory between a parent process and a child process.
0
Attacker Value
Unknown

CVE-2012-6542

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel before 3.6 has an incorrect return value in certain circumstances, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that leverages an uninitialized pointer argument.
0
Attacker Value
Unknown

CVE-2012-6538

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorrect C library function for copying a string, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability.
0
Attacker Value
Unknown

CVE-2012-6544

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that targets the (1) L2CAP or (2) HCI implementation.
0