CVE-2008-3496 describes a critical buffer overflow vulnerability in the uvc_parse_format function within the uvcvideo driver of the Linux kernel, affecting versions prior to 2.6.26.1. This flaw, rated with a CVSS score of 10.0, allows for remote, unauthenticated attacks with complete compromise of confidentiality, integrity, and availability. Despite its severe nature, there is no known exploit code available in public databases like Metasploit or ExploitDB, and it shows minimal community discussion or media coverage, suggesting a low current exploitation risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.26.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.