Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-8091

Опубликовано: 10 дек. 2014
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver and xorg-server) before 1.16.3, when using SUN-DES-1 (Secure RPC) authentication credentials, does not check the return value of a malloc call, which allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a crafted connection request.

Комментарий

CWE-476: NULL Pointer Dereference

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:x.org:xorg-server:*:*:*:*:*:*:*:*
Версия до 1.16.2 (включая)
Конфигурация 2
cpe:2.3:a:x.org:x11:5.0:*:*:*:*:*:*:*

EPSS

Процентиль: 91%
0.06313
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
больше 10 лет назад

X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver and xorg-server) before 1.16.3, when using SUN-DES-1 (Secure RPC) authentication credentials, does not check the return value of a malloc call, which allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a crafted connection request.

redhat
больше 10 лет назад

X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver and xorg-server) before 1.16.3, when using SUN-DES-1 (Secure RPC) authentication credentials, does not check the return value of a malloc call, which allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a crafted connection request.

debian
больше 10 лет назад

X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xser ...

github
больше 3 лет назад

X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver and xorg-server) before 1.16.3, when using SUN-DES-1 (Secure RPC) authentication credentials, does not check the return value of a malloc call, which allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a crafted connection request.

oracle-oval
больше 10 лет назад

ELSA-2014-1982: xorg-x11-server security update (IMPORTANT)

EPSS

Процентиль: 91%
0.06313
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other