Lucene search

K
nvd[email protected]NVD:CVE-2014-3182
HistorySep 28, 2014 - 10:55 a.m.

CVE-2014-3182

2014-09-2810:55:10
CWE-119
web.nvd.nist.gov

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.1%

Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provides a malformed REPORT_TYPE_NOTIF_DEVICE_UNPAIRED value.

Affected configurations

NVD
Node
linuxlinux_kernelRange<3.2.63
OR
linuxlinux_kernelRange3.33.4.104
OR
linuxlinux_kernelRange3.53.10.54
OR
linuxlinux_kernelRange3.113.12.28
OR
linuxlinux_kernelRange3.133.14.18
OR
linuxlinux_kernelRange3.153.16.2

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.1%