Show filters
120 Total Results
Displaying 71-80 of 120
Sort by:
Attacker Value
Unknown

CVE-2013-2015

Disclosure Date: April 29, 2013 (last updated October 05, 2023)
The ext4_orphan_del function in fs/ext4/namei.c in the Linux kernel before 3.7.3 does not properly handle orphan-list entries for non-journal filesystems, which allows physically proximate attackers to cause a denial of service (system hang) via a crafted filesystem on removable media, as demonstrated by the e2fsprogs tests/f_orphan_extents_inode/image.gz test.
0
Attacker Value
Unknown

CVE-2013-1858

Disclosure Date: April 05, 2013 (last updated October 05, 2023)
The clone system-call implementation in the Linux kernel before 3.8.3 does not properly handle a combination of the CLONE_NEWUSER and CLONE_FS flags, which allows local users to gain privileges by calling chroot and leveraging the sharing of the / directory between a parent process and a child process.
0
Attacker Value
Unknown

CVE-2012-6542

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel before 3.6 has an incorrect return value in certain circumstances, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that leverages an uninitialized pointer argument.
0
Attacker Value
Unknown

CVE-2012-6538

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorrect C library function for copying a string, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability.
0
Attacker Value
Unknown

CVE-2012-6544

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that targets the (1) L2CAP or (2) HCI implementation.
0
Attacker Value
Unknown

CVE-2012-6546

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
The ATM implementation in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
0
Attacker Value
Unknown

CVE-2012-6540

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
The do_ip_vs_get_ctl function in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 3.6 does not initialize a certain structure for IP_VS_SO_GET_TIMEOUT commands, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
0
Attacker Value
Unknown

CVE-2013-2548

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect length value during a copy operation, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability.
0
Attacker Value
Unknown

CVE-2013-2547

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 does not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability.
0
Attacker Value
Unknown

CVE-2012-6536

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not verify that the actual Netlink message length is consistent with a certain header field, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability and providing a (1) new or (2) updated state.
0