- EPSS 0.05%
- Veröffentlicht 08.06.2013 13:05:55
- Zuletzt bearbeitet 29.04.2026 01:13:23
The kvm_vm_ioctl_assign_device function in virt/kvm/assigned-dev.c in the KVM subsystem in the Linux kernel before 3.1.10 does not verify permission to access PCI configuration space and BAR resources, which allows host OS users to assign PCI devices...
- EPSS 0.05%
- Veröffentlicht 07.06.2013 14:03:20
- Zuletzt bearbeitet 29.04.2026 01:13:23
Format string vulnerability in the register_disk function in block/genhd.c in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and writing format string specifiers to /sys/module/md_mod/parameters/new_arr...
CVE-2013-2852
- EPSS 0.21%
- Veröffentlicht 07.06.2013 14:03:20
- Zuletzt bearbeitet 29.04.2026 01:13:23
Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including fo...
CVE-2013-2146
- EPSS 0.04%
- Veröffentlicht 07.06.2013 14:03:19
- Zuletzt bearbeitet 29.04.2026 01:13:23
arch/x86/kernel/cpu/perf_event_intel.c in the Linux kernel before 3.8.9, when the Performance Events Subsystem is enabled, specifies an incorrect bitmask, which allows local users to cause a denial of service (general protection fault and system cras...
CVE-2013-2147
- EPSS 0.08%
- Veröffentlicht 07.06.2013 14:03:19
- Zuletzt bearbeitet 29.04.2026 01:13:23
The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3.9.4 do not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory vi...
CVE-2013-2148
- EPSS 0.06%
- Veröffentlicht 07.06.2013 14:03:19
- Zuletzt bearbeitet 29.04.2026 01:13:23
The fill_event_metadata function in fs/notify/fanotify/fanotify_user.c in the Linux kernel through 3.9.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a read operation ...
CVE-2013-2850
- EPSS 13.32%
- Veröffentlicht 07.06.2013 14:03:19
- Zuletzt bearbeitet 29.04.2026 01:13:23
Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters.c in the iSCSI target subsystem in the Linux kernel through 3.9.4 allows remote attackers to cause a denial of service (memory...
CVE-2013-1929
- EPSS 0.12%
- Veröffentlicht 07.06.2013 14:03:18
- Zuletzt bearbeitet 29.04.2026 01:13:23
Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3.c in the Linux kernel before 3.8.6 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via c...
CVE-2013-2141
- EPSS 0.03%
- Veröffentlicht 07.06.2013 14:03:18
- Zuletzt bearbeitet 29.04.2026 01:13:23
The do_tkill function in kernel/signal.c in the Linux kernel before 3.8.9 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via a crafted application that makes a (1) tkill or (2...
CVE-2013-2094
- EPSS 65.85%
- Veröffentlicht 14.05.2013 20:55:01
- Zuletzt bearbeitet 22.04.2026 14:38:13
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.