CVE-2014-3290
published 2014-06-14CVE-2014-3290: The mDNS implementation in Cisco IOS XE 3.12S does not properly interact with autonomic networking, which allows remote attackers to obtain sensitive…
PriorityP421medium4.8CVSS 2.0
AVAACLAuNCPIPAN
EPSS
1.15%
63.5th percentile
The mDNS implementation in Cisco IOS XE 3.12S does not properly interact with autonomic networking, which allows remote attackers to obtain sensitive networking-services information by sniffing the network or overwrite networking-services data via a crafted mDNS response, aka Bug ID CSCun64867.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xe | — | — |
| linux | linux_kernel | >= 5.6.0 < 6.1.160 | 6.1.160 |
| linux | linux_kernel | >= 6.13.0 < 6.18.3 | 6.18.3 |
| linux | linux_kernel | >= 6.2.0 < 6.6.120 | 6.6.120 |
| linux | linux_kernel | >= 6.7.0 < 6.12.64 | 6.12.64 |
CVSS provenance
nvdv2.04.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:N
vendor_cisco4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XE Software Autonomic Networking Infrastructure Overwrite Vulnerability
vendor_cisco·2014-06-13·CVSS 4.8
CVE-2014-3290 [MEDIUM] Cisco IOS XE Software Autonomic Networking Infrastructure Overwrite Vulnerability
Cisco IOS XE Software Autonomic Networking Infrastructure Overwrite Vulnerability
A vulnerability in the multicast Domain Name System (mDNS) used for autonomic networking in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to read or overwrite autonomic networking services discovered via mDNS.
The vulnerability is due to unconstrained autonomic networking mDNS. An attacker could exploit this vulnerability by capturing data on the segment or sending crafted mDNS responses.
Cisco has confirmed the vulnerability in a security notice and released software updates.
Although an attacker does not need to authenticate to a targeted device to exploit this vulnerability, the attacker must have access to the same collision or broadcast domain of the device to attempt an ex
OSV
f2fs: fix to avoid updating compression context during writeback
osv·2026-01-13
CVE-2025-68772 f2fs: fix to avoid updating compression context during writeback
f2fs: fix to avoid updating compression context during writeback
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to avoid updating compression context during writeback
Bai, Shuangpeng reported a bug as below:
Oops: divide error: 0000 [#1] SMP KASAN PTI
CPU: 0 UID: 0 PID: 11441 Comm: syz.0.46 Not tainted 6.17.0 #1 PREEMPT(full)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
RIP: 0010:f2fs_all_cluster_page_ready+0x106/0x550 fs/f2fs/compress.c:857
Call Trace:
f2fs_write_cache_pages fs/f2fs/data.c:3078 [inline]
__f2fs_write_data_pages fs/f2fs/data.c:3290 [inline]
f2fs_write_data_pages+0x1c19/0x3600 fs/f2fs/data.c:3317
do_writepages+0x38e/0x640 mm/page-writeback.c:2634
filemap_fdatawrite_wbc mm/filemap.c:386 [inline]
__filemap_
GHSA
GHSA-px85-wqgv-cw85: The mDNS implementation in Cisco IOS XE 3
ghsa_unreviewed·2022-05-17
CVE-2014-3290 [MEDIUM] GHSA-px85-wqgv-cw85: The mDNS implementation in Cisco IOS XE 3
The mDNS implementation in Cisco IOS XE 3.12S does not properly interact with autonomic networking, which allows remote attackers to obtain sensitive networking-services information by sniffing the network or overwrite networking-services data via a crafted mDNS response, aka Bug ID CSCun64867.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/58715http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3290http://tools.cisco.com/security/center/viewAlert.x?alertId=34613http://www.securityfocus.com/bid/68021http://www.securitytracker.com/id/1030444http://secunia.com/advisories/58715http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3290http://tools.cisco.com/security/center/viewAlert.x?alertId=34613http://www.securityfocus.com/bid/68021http://www.securitytracker.com/id/1030444
2014-06-14
Published