Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2016-4482

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 3.2%
CVSS Severity
CVSS v3 Score 6.2
CVSS v2 Score 2.1
References
Products affected by CVE-2016-4482


Contact Us

Shodan ® - All rights reserved