Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pcjv-393q-rqf2

Опубликовано: 18 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used.

A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used.

EPSS

Процентиль: 86%
0.03081
Низкий

7.8 High

CVSS3

Дефекты

CWE-119
CWE-787

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 2 года назад

A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used.

CVSS3: 9.8
redhat
почти 2 года назад

A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used.

CVSS3: 9.8
nvd
почти 2 года назад

A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used.

CVSS3: 9.8
msrc
почти 2 года назад

Xorg-x11-server: heap buffer overflow in devicefocusevent and procxiquerypointer

CVSS3: 9.8
debian
почти 2 года назад

A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQuer ...

EPSS

Процентиль: 86%
0.03081
Низкий

7.8 High

CVSS3

Дефекты

CWE-119
CWE-787