CVE-2013-4740
Last modified
CVE-2013-4740 is a vulnerability of currently unknown severity. goodix_tool.c in the Goodix gt915 touchscreen driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, relies on user-space length values for kernel-memory copies of procfs file content, which allows attackers to gain privileges or cause a denial of service (memory corruption) via an application that provides crafted values.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
goodix_tool.c in the Goodix gt915 touchscreen driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, relies on user-space length values for kernel-memory copies of procfs file content, which allows attackers to gain privileges or cause a denial of service (memory corruption) via an application that provides crafted values.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Quic Mobile Station Modem Kernel | 3.10 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4740?
How severe is CVE-2013-4740?
How do I fix CVE-2013-4740?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-4734dasdec_mkuser on the Digital Alert Systems DASDEC EAS device…7.3
- CVE-2013-4735The Digital Alert Systems DASDEC EAS device before 2.0-2 and…
- CVE-2013-4736Multiple integer overflows in the JPEG engine drivers in the…
- CVE-2013-4737The CONFIG_STRICT_MEMORY_RWX implementation for the Linux ke…
- CVE-2013-4738Multiple stack-based buffer overflows in the MSM camera driv…
- CVE-2013-4739The MSM camera driver for the Linux kernel 3.x, as used in Q…
- CVE-2013-4742Buffer overflow in NetWin SurgeFTP before 23d2 allows remote…
- CVE-2013-4743Static HTTP Server 1.0 has a Local Overflow9.8
- CVE-2013-4744Cross-site scripting (XSS) vulnerability in the PHPUnit exte…
- CVE-2013-4745SQL injection vulnerability in the My quiz and poll (myquizp…
- CVE-2013-4746Cross-site scripting (XSS) vulnerability in the My quiz and …
- CVE-2013-4747Cross-site scripting (XSS) vulnerability in the Accessible b…
Are you affected by CVE-2013-4740?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
