cbcvebase.
CVE-2014-3186
published 2014-09-28

CVE-2014-3186: Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as…

PriorityP430medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.70%
49.7th percentile
Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as used in Android on Nexus 7 devices, allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that sends a large report.

Affected

14 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 3.16.5-1 (bookworm)linux 3.16.5-1 (bookworm)
linuxlinux_kernel>= 0 < 3.16.5-13.16.5-1
linuxlinux_kernel>= 0 < 3.16.5-13.16.5-1
linuxlinux_kernel>= 0 < 3.16.5-13.16.5-1
linuxlinux_kernel>= 0 < 3.16.5-13.16.5-1
linuxlinux_kernel>= 0 < 3.13.0-37.643.13.0-37.64
linuxlinux_kernel>= 2.6.35 < 3.2.633.2.63
linuxlinux_kernel>= 3.11 < 3.12.313.12.31
linuxlinux_kernel>= 3.13 < 3.14.203.14.20
linuxlinux_kernel>= 3.15 < 3.16.43.16.4
linuxlinux_kernel>= 3.3 < 3.4.1043.4.104
linuxlinux_kernel>= 3.5 < 3.10.563.10.56

CVSS provenance

nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.