VDB
CVE-2013-2597
CVE-2013-2597
PUBLISHED
KEV
CVSS 8.399999618530273 HIGH
Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument.
EPSS 1.50% · 73.1th percentile
Risk Scores
CVSS 3.1
8.399999618530273
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.50%
73.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| codeaurora | android-msm | 3.10.29, 3.2.54, 3.2.55 |
| n/a | n/a | n/a |
Timeline
- Jun 11, 2013 VulnCheck XDB Entry
- Aug 31, 2014 CVE Published
- Dec 3, 2017 PoC Published
- Feb 4, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 15, 2022 CISA KEV Added
- Sep 15, 2022 VulnCheck KEV Exploitation
- Oct 28, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 5, 2023 EPSS Score