CVE-2013-4270
- EPSS 0.04%
- Veröffentlicht 09.12.2013 18:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
The net_ctl_permissions function in net/sysctl_net.c in the Linux kernel before 3.11.5 does not properly determine uid and gid values, which allows local users to bypass intended /proc/sys/net restrictions via a crafted application.
CVE-2013-6378
- EPSS 0.02%
- Veröffentlicht 27.11.2013 04:43:33
- Zuletzt bearbeitet 11.04.2025 00:51:21
The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service (OOPS) by leveraging root privileges for a zero-length write operation.
CVE-2013-6380
- EPSS 0.06%
- Veröffentlicht 27.11.2013 04:43:33
- Zuletzt bearbeitet 11.04.2025 00:51:21
The aac_send_raw_srb function in drivers/scsi/aacraid/commctrl.c in the Linux kernel through 3.12.1 does not properly validate a certain size value, which allows local users to cause a denial of service (invalid pointer dereference) or possibly have ...
CVE-2013-6381
- EPSS 0.09%
- Veröffentlicht 27.11.2013 04:43:33
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in the qeth_snmp_command function in drivers/s390/net/qeth_core_main.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service or possibly have unspecified other impact via an SNMP ioctl call with a length v...
- EPSS 0.01%
- Veröffentlicht 27.11.2013 04:43:33
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple buffer underflows in the XFS implementation in the Linux kernel through 3.12.1 allow local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for a (1) ...
CVE-2013-6383
- EPSS 0.03%
- Veröffentlicht 27.11.2013 04:43:33
- Zuletzt bearbeitet 11.04.2025 00:51:21
The aac_compat_ioctl function in drivers/scsi/aacraid/linit.c in the Linux kernel before 3.11.8 does not require the CAP_SYS_RAWIO capability, which allows local users to bypass intended access restrictions via a crafted ioctl call.
CVE-2013-6282
- EPSS 51.24%
- Veröffentlicht 20.11.2013 13:19:43
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a craft...
- EPSS 0.05%
- Veröffentlicht 20.11.2013 13:19:42
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 2.6.33, when CONFIG_IP_VS is used, allow local users to gain privileges by leveraging the CAP_NET_ADMIN capability for (1) a getsockopt system call, re...
CVE-2013-4591
- EPSS 0.06%
- Veröffentlicht 20.11.2013 13:19:42
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the Linux kernel before 3.7.2 allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via a getxatt...
- EPSS 0.04%
- Veröffentlicht 20.11.2013 13:19:42
- Zuletzt bearbeitet 11.04.2025 00:51:21
Memory leak in the __kvm_set_memory_region function in virt/kvm/kvm_main.c in the Linux kernel before 3.9 allows local users to cause a denial of service (memory consumption) by leveraging certain device access to trigger movement of memory slots.