cbcvebase.
CVE-2014-3182
published 2014-09-28

CVE-2014-3182: Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to…

PriorityP427medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.43%
35.3th percentile
Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provides a malformed REPORT_TYPE_NOTIF_DEVICE_UNPAIRED value.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.16.2-2 (bookworm)linux 3.16.2-2 (bookworm)
linuxlinux_kernel< 3.2.633.2.63
linuxlinux_kernel>= 0 < 3.16.2-23.16.2-2
linuxlinux_kernel>= 0 < 3.16.2-23.16.2-2
linuxlinux_kernel>= 0 < 3.16.2-23.16.2-2
linuxlinux_kernel>= 0 < 3.16.2-23.16.2-2
linuxlinux_kernel>= 0 < 3.13.0-39.663.13.0-39.66
linuxlinux_kernel>= 3.11 < 3.12.283.12.28
linuxlinux_kernel>= 3.13 < 3.14.183.14.18
linuxlinux_kernel>= 3.15 < 3.16.23.16.2
linuxlinux_kernel>= 3.3 < 3.4.1043.4.104
linuxlinux_kernel>= 3.5 < 3.10.543.10.54

CVSS provenance

nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.