cbcvebase.
CVE-2014-3183
published 2014-09-28

CVE-2014-3183: Heap-based buffer overflow in the logi_dj_ll_raw_request function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically…

PriorityP430medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.50%
40.0th percentile
Heap-based buffer overflow in the logi_dj_ll_raw_request function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that specifies a large report size for an LED report.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.16.2-2 (bookworm)linux 3.16.2-2 (bookworm)
linuxlinux_kernel>= 0 < 3.16.2-23.16.2-2
linuxlinux_kernel>= 0 < 3.16.2-23.16.2-2
linuxlinux_kernel>= 0 < 3.16.2-23.16.2-2
linuxlinux_kernel>= 0 < 3.16.2-23.16.2-2
linuxlinux_kernel>= 3.15 < 3.16.23.16.2

CVSS provenance

nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.