← back
CVE-2010-2963

CVE-2010-2963

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 0.8%
from disclosure to weapon0 days
Published on NVDNov 26
1st PoCOct 28
exploitation probability
0.8%top 46% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local users to write to arbitrary kernel memory locations, and consequently gain privileges, via a VIDIOCSTUNER ioctl call on a /dev/video device, followed by a VIDIOCSMICROCODE ioctl call on this device.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.