CVE-2013-4348
- EPSS 4.27%
- Veröffentlicht 04.11.2013 15:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of service (infinite loop) via a small value in the IHL field of a packet with IPIP encapsulation.
CVE-2013-4470
- EPSS 0.12%
- Veröffentlicht 04.11.2013 15:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Linux kernel before 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly initialize certain data structures, which allows local users to cause a denial of service (memory corruption and system crash) or possibly gain privilege...
CVE-2013-4483
- EPSS 0.09%
- Veröffentlicht 04.11.2013 15:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ipc_rcu_putref function in ipc/util.c in the Linux kernel before 3.10 does not properly manage a reference count, which allows local users to cause a denial of service (memory consumption or system crash) via a crafted application.
- EPSS 0.8%
- Veröffentlicht 24.10.2013 10:53:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel through 3.11.6 allows remote authenticated users to obtain sensitive information or modify data via a crafted mapping to a snapshot block device.
CVE-2013-4345
- EPSS 0.96%
- Veröffentlicht 10.10.2013 10:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via multiple requests for small amounts of data, l...
CVE-2013-4387
- EPSS 0.84%
- Veröffentlicht 10.10.2013 10:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
net/ipv6/ip6_output.c in the Linux kernel through 3.11.4 does not properly determine the need for UDP Fragmentation Offload (UFO) processing of small packets after the UFO queueing of a large packet, which allows remote attackers to cause a denial of...
CVE-2013-2140
- EPSS 0.13%
- Veröffentlicht 25.09.2013 10:31:29
- Zuletzt bearbeitet 11.04.2025 00:51:21
The dispatch_discard_io function in drivers/block/xen-blkback/blkback.c in the Xen blkback implementation in the Linux kernel before 3.10.5 allows guest OS users to cause a denial of service (data loss) via filesystem write operations on a read-only ...
CVE-2013-4300
- EPSS 0.04%
- Veröffentlicht 25.09.2013 10:31:29
- Zuletzt bearbeitet 11.04.2025 00:51:21
The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 performs a capability check in an incorrect namespace, which allows local users to gain privileges via PID spoofing.
CVE-2013-4343
- EPSS 0.09%
- Veröffentlicht 25.09.2013 10:31:29
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in drivers/net/tun.c in the Linux kernel through 3.11.1 allows local users to gain privileges by leveraging the CAP_NET_ADMIN capability and providing an invalid tuntap interface name in a TUNSETIFF ioctl call.
- EPSS 0.33%
- Veröffentlicht 25.09.2013 10:31:29
- Zuletzt bearbeitet 11.04.2025 00:51:21
The IPv6 SCTP implementation in net/sctp/ipv6.c in the Linux kernel through 3.11.1 uses data structures and function calls that do not trigger an intended configuration of IPsec encryption, which allows remote attackers to obtain sensitive informatio...