CVE-2013-4270
- EPSS 0.55%
- Veröffentlicht 09.12.2013 18:55:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
The net_ctl_permissions function in net/sysctl_net.c in the Linux kernel before 3.11.5 does not properly determine uid and gid values, which allows local users to bypass intended /proc/sys/net restrictions via a crafted application.
CVE-2013-6378
- EPSS 0.38%
- Veröffentlicht 27.11.2013 04:43:33
- Zuletzt bearbeitet 29.04.2026 01:13:23
The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service (OOPS) by leveraging root privileges for a zero-length write operation.
CVE-2013-6380
- EPSS 0.6%
- Veröffentlicht 27.11.2013 04:43:33
- Zuletzt bearbeitet 29.04.2026 01:13:23
The aac_send_raw_srb function in drivers/scsi/aacraid/commctrl.c in the Linux kernel through 3.12.1 does not properly validate a certain size value, which allows local users to cause a denial of service (invalid pointer dereference) or possibly have ...
CVE-2013-6381
- EPSS 0.57%
- Veröffentlicht 27.11.2013 04:43:33
- Zuletzt bearbeitet 29.04.2026 01:13:23
Buffer overflow in the qeth_snmp_command function in drivers/s390/net/qeth_core_main.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service or possibly have unspecified other impact via an SNMP ioctl call with a length v...
- EPSS 0.58%
- Veröffentlicht 27.11.2013 04:43:33
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple buffer underflows in the XFS implementation in the Linux kernel through 3.12.1 allow local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for a (1) ...
CVE-2013-6383
- EPSS 0.49%
- Veröffentlicht 27.11.2013 04:43:33
- Zuletzt bearbeitet 29.04.2026 01:13:23
The aac_compat_ioctl function in drivers/scsi/aacraid/linit.c in the Linux kernel before 3.11.8 does not require the CAP_SYS_RAWIO capability, which allows local users to bypass intended access restrictions via a crafted ioctl call.
CVE-2013-6282
- EPSS 39.71%
- Veröffentlicht 20.11.2013 13:19:43
- Zuletzt bearbeitet 22.04.2026 13:54:12
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a craft...
CVE-2013-4591
- EPSS 0.57%
- Veröffentlicht 20.11.2013 13:19:42
- Zuletzt bearbeitet 29.04.2026 01:13:23
Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the Linux kernel before 3.7.2 allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via a getxatt...
CVE-2013-4563
- EPSS 3.9%
- Veröffentlicht 20.11.2013 13:19:41
- Zuletzt bearbeitet 29.04.2026 01:13:23
The udp6_ufo_fragment function in net/ipv6/udp_offload.c in the Linux kernel through 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly perform a certain size comparison before inserting a fragment header, which allows remote at...
CVE-2013-4579
- EPSS 10.21%
- Veröffentlicht 20.11.2013 13:19:41
- Zuletzt bearbeitet 29.04.2026 01:13:23
The ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12 uses a BSSID masking approach to determine the set of MAC addresses on which a Wi-Fi device is listening, which allows remote atta...