CVE-2013-1959
- EPSS 1.05%
- Published 03.05.2013 11:57:45
- Last modified 11.04.2025 00:51:21
kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_map and gid_map files, which allows local users to gain privileges by opening a file within an unprivileged process and then modify...
CVE-2013-1979
- EPSS 0.04%
- Published 03.05.2013 11:57:45
- Last modified 11.04.2025 00:51:21
The scm_set_cred function in include/net/scm.h in the Linux kernel before 3.8.11 uses incorrect uid and gid values during credentials passing, which allows local users to gain privileges via a crafted application.
CVE-2013-2017
- EPSS 1.18%
- Published 03.05.2013 11:57:45
- Last modified 11.04.2025 00:51:21
The veth (aka virtual Ethernet) driver in the Linux kernel before 2.6.34 does not properly manage skbs during congestion, which allows remote attackers to cause a denial of service (system crash) by leveraging lack of skb consumption in conjunction w...
CVE-2013-2015
- EPSS 0.09%
- Published 29.04.2013 14:55:04
- Last modified 11.04.2025 00:51:21
The ext4_orphan_del function in fs/ext4/namei.c in the Linux kernel before 3.7.3 does not properly handle orphan-list entries for non-journal filesystems, which allows physically proximate attackers to cause a denial of service (system hang) via a cr...
CVE-2013-3301
- EPSS 0.34%
- Published 29.04.2013 14:55:04
- Last modified 11.04.2025 00:51:21
The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write acce...
CVE-2013-3302
- EPSS 0.05%
- Published 29.04.2013 14:55:04
- Last modified 11.04.2025 00:51:21
Race condition in the smb_send_rqst function in fs/cifs/transport.c in the Linux kernel before 3.7.2 allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors involving a...
CVE-2013-1928
- EPSS 0.06%
- Published 29.04.2013 14:55:03
- Last modified 11.04.2025 00:51:21
The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel before 3.6.5 on unspecified architectures lacks a certain error check, which might allow local users to obtain sensitive information from kernel stack memory via a crafted...
CVE-2013-1956
- EPSS 0.03%
- Published 24.04.2013 19:55:01
- Last modified 11.04.2025 00:51:21
The create_user_ns function in kernel/user_namespace.c in the Linux kernel before 3.8.6 does not check whether a chroot directory exists that differs from the namespace root directory, which allows local users to bypass intended filesystem restrictio...
CVE-2013-1957
- EPSS 0.04%
- Published 24.04.2013 19:55:01
- Last modified 11.04.2025 00:51:21
The clone_mnt function in fs/namespace.c in the Linux kernel before 3.8.6 does not properly restrict changes to the MNT_READONLY flag, which allows local users to bypass an intended read-only property of a filesystem by leveraging a separate mount na...
CVE-2013-1958
- EPSS 0.04%
- Published 24.04.2013 19:55:01
- Last modified 11.04.2025 00:51:21
The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.8.6 does not properly enforce capability requirements for controlling the PID value associated with a UNIX domain socket, which allows local users to bypass intended access r...