CVE-2013-3232
- EPSS 0.06%
- Veröffentlicht 22.04.2013 11:41:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The nr_recvmsg function in net/netrom/af_netrom.c in the Linux kernel before 3.9-rc7 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom sys...
CVE-2013-3233
- EPSS 0.05%
- Veröffentlicht 22.04.2013 11:41:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The llcp_sock_recvmsg function in net/nfc/llcp/sock.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable and a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via...
CVE-2013-3234
- EPSS 0.05%
- Veröffentlicht 22.04.2013 11:41:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The rose_recvmsg function in net/rose/af_rose.c in the Linux kernel before 3.9-rc7 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom syste...
CVE-2013-3235
- EPSS 0.07%
- Veröffentlicht 22.04.2013 11:41:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
net/tipc/socket.c in the Linux kernel before 3.9-rc7 does not initialize a certain data structure and a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom syste...
CVE-2013-3236
- EPSS 0.05%
- Veröffentlicht 22.04.2013 11:41:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The vmci_transport_dgram_dequeue function in net/vmw_vsock/vmci_transport.c in the Linux kernel before 3.9-rc7 does not properly initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory v...
CVE-2013-3237
- EPSS 0.05%
- Veröffentlicht 22.04.2013 11:41:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The vsock_stream_sendmsg function in net/vmw_vsock/af_vsock.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or...
CVE-2013-3076
- EPSS 0.06%
- Veröffentlicht 22.04.2013 11:40:59
- Zuletzt bearbeitet 11.04.2025 00:51:21
The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call, related to the hash_recv...
CVE-2013-2596
- EPSS 1.74%
- Veröffentlicht 13.04.2013 02:59:46
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of ...
CVE-2013-1858
- EPSS 0.65%
- Veröffentlicht 05.04.2013 21:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The clone system-call implementation in the Linux kernel before 3.8.3 does not properly handle a combination of the CLONE_NEWUSER and CLONE_FS flags, which allows local users to gain privileges by calling chroot and leveraging the sharing of the / di...
CVE-2013-2636
- EPSS 0.11%
- Veröffentlicht 22.03.2013 11:59:12
- Zuletzt bearbeitet 11.04.2025 00:51:21
net/bridge/br_mdb.c in the Linux kernel before 3.8.4 does not initialize certain structures, which allows local users to obtain sensitive information from kernel memory via a crafted application.