Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8096

Опубликовано: 09 дек. 2014
Источник: redhat
CVSS2: 2.3
EPSS Низкий

Описание

The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X) X11R6.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value.

Multiple out-of-bounds access flaws were found in the way the X.Org server calculated memory requirements for certain requests. A malicious, authenticated client could use either of these flaws to crash the X.Org server.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-805->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1168700xorg-x11-server: out of bounds access due to not validating length or offset values in XC-MISC extension

EPSS

Процентиль: 76%
0.01014
Низкий

2.3 Low

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X) X11R6.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value.

nvd
больше 10 лет назад

The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X) X11R6.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value.

debian
больше 10 лет назад

The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X ...

github
больше 3 лет назад

The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X) X11R6.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value.

oracle-oval
больше 10 лет назад

ELSA-2014-1982: xorg-x11-server security update (IMPORTANT)

EPSS

Процентиль: 76%
0.01014
Низкий

2.3 Low

CVSS2