Show filters
112 Total Results
Displaying 91-100 of 112
Sort by:
Attacker Value
Unknown
CVE-2013-1767
Disclosure Date: February 28, 2013 (last updated October 05, 2023)
Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in the Linux kernel before 3.7.10 allows local users to gain privileges or cause a denial of service (system crash) by remounting a tmpfs filesystem without specifying a required mpol (aka mempolicy) mount option.
0
Attacker Value
Unknown
CVE-2013-1772
Disclosure Date: February 28, 2013 (last updated October 05, 2023)
The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and system crash) by leveraging /dev/kmsg write access and triggering a call_console_drivers function call.
0
Attacker Value
Unknown
CVE-2013-0343
Disclosure Date: February 28, 2013 (last updated October 05, 2023)
The ipv6_create_tempaddr function in net/ipv6/addrconf.c in the Linux kernel through 3.8 does not properly handle problems with the generation of IPv6 temporary addresses, which allows remote attackers to cause a denial of service (excessive retries and address-generation outage), and consequently obtain sensitive information, via ICMPv6 Router Advertisement (RA) messages.
0
Attacker Value
Unknown
CVE-2012-4542
Disclosure Date: February 28, 2013 (last updated October 05, 2023)
block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcodes.
0
Attacker Value
Unknown
CVE-2013-1774
Disclosure Date: February 28, 2013 (last updated October 05, 2023)
The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before 3.7.4 allows local users to cause a denial of service (NULL pointer dereference and system crash) via an attempted /dev/ttyUSB read or write operation on a disconnected Edgeport USB serial converter.
0
Attacker Value
Unknown
CVE-2013-0349
Disclosure Date: February 28, 2013 (last updated October 05, 2023)
The hidp_setup_hid function in net/bluetooth/hidp/core.c in the Linux kernel before 3.7.6 does not properly copy a certain name field, which allows local users to obtain sensitive information from kernel memory by setting a long name and making an HIDPCONNADD ioctl call.
0
Attacker Value
Unknown
CVE-2013-0313
Disclosure Date: February 22, 2013 (last updated October 05, 2023)
The evm_update_evmxattr function in security/integrity/evm/evm_crypto.c in the Linux kernel before 3.7.5, when the Extended Verification Module (EVM) is enabled, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an attempted removexattr operation on an inode of a sockfs filesystem.
0
Attacker Value
Unknown
CVE-2013-0311
Disclosure Date: February 22, 2013 (last updated October 05, 2023)
The translate_desc function in drivers/vhost/vhost.c in the Linux kernel before 3.7 does not properly handle cross-region descriptors, which allows guest OS users to obtain host OS privileges by leveraging KVM guest OS privileges.
0
Attacker Value
Unknown
CVE-2013-0309
Disclosure Date: February 22, 2013 (last updated October 05, 2023)
arch/x86/include/asm/pgtable.h in the Linux kernel before 3.6.2, when transparent huge pages are used, does not properly support PROT_NONE memory regions, which allows local users to cause a denial of service (system crash) via a crafted application.
0
Attacker Value
Unknown
CVE-2013-0290
Disclosure Date: February 19, 2013 (last updated October 05, 2023)
The __skb_recv_datagram function in net/core/datagram.c in the Linux kernel before 3.8 does not properly handle the MSG_PEEK flag with zero-length data, which allows local users to cause a denial of service (infinite loop and system hang) via a crafted application.
0