8.5
CVE-2007-1351
- EPSS 7.49%
- Published 06.04.2007 01:19:00
- Last modified 09.04.2025 00:30:58
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.
Data is provided by the National Vulnerability Database (NVD)
Ubuntu ≫ Ubuntu Linux Version5.10 Editionamd64
Ubuntu ≫ Ubuntu Linux Version5.10 Editioni386
Ubuntu ≫ Ubuntu Linux Version5.10 Editionpowerpc
Ubuntu ≫ Ubuntu Linux Version5.10 Editionsparc
Ubuntu ≫ Ubuntu Linux Version6.06_lts Editionamd64
Ubuntu ≫ Ubuntu Linux Version6.06_lts Editioni386
Ubuntu ≫ Ubuntu Linux Version6.06_lts Editionpowerpc
Ubuntu ≫ Ubuntu Linux Version6.06_lts Editionsparc
Ubuntu ≫ Ubuntu Linux Version6.10 Editionamd64
Ubuntu ≫ Ubuntu Linux Version6.10 Editioni386
Ubuntu ≫ Ubuntu Linux Version6.10 Editionpowerpc
Ubuntu ≫ Ubuntu Linux Version6.10 Editionsparc
Xfree86 Project ≫ X11r6 Version4.3.0
Xfree86 Project ≫ X11r6 Version4.3.0.1
Xfree86 Project ≫ X11r6 Version4.3.0.2
Rpath ≫ Rpath Linux Version1
Redhat ≫ Enterprise Linux Version2.1 Editionadvanced_server
Redhat ≫ Enterprise Linux Version2.1 Editionadvanced_server_ia64
Redhat ≫ Enterprise Linux Version2.1 Editionenterprise_server
Redhat ≫ Enterprise Linux Version2.1 Editionenterprise_server_ia64
Redhat ≫ Enterprise Linux Version2.1 Editionworkstation
Redhat ≫ Enterprise Linux Version2.1 Editionworkstation_ia64
Redhat ≫ Enterprise Linux Version3.0 Editionadvanced_servers
Redhat ≫ Enterprise Linux Version3.0 Editionenterprise_server
Redhat ≫ Enterprise Linux Version3.0 Editionworkstation
Redhat ≫ Enterprise Linux Version4.0 Editionadvanced_server
Redhat ≫ Enterprise Linux Version4.0 Editionenterprise_server
Redhat ≫ Enterprise Linux Version4.0 Editionworkstation
Redhat ≫ Enterprise Linux Version5.0 Editiondesktop
Redhat ≫ Enterprise Linux Version5.0 Editiondesktop_workstation
Redhat ≫ Enterprise Linux Version5.0 Editionserver
Redhat ≫ Enterprise Linux Desktop Version3.0
Redhat ≫ Enterprise Linux Desktop Version4.0
Redhat ≫ Linux Advanced Workstation Version2.1 Editionia64
Redhat ≫ Linux Advanced Workstation Version2.1 Editionitanium
Mandrakesoft ≫ Mandrake Multi Network Firewall Version2.0
Mandrakesoft ≫ Mandrake Linux Version2007
Mandrakesoft ≫ Mandrake Linux Version2007 Editionx86_64
Mandrakesoft ≫ Mandrake Linux Corporate Server Version3.0
Mandrakesoft ≫ Mandrake Linux Corporate Server Version3.0 Editionx86_64
Mandrakesoft ≫ Mandrake Linux Corporate Server Version4.0
Mandrakesoft ≫ Mandrake Linux Corporate Server Version4.0 Editionx86_64
Mandrakesoft ≫ Mandrake Linux Version2007 Editionx86_64
Mandrakesoft ≫ Mandrake Linux Corporate Server Version3.0
Mandrakesoft ≫ Mandrake Linux Corporate Server Version3.0 Editionx86_64
Mandrakesoft ≫ Mandrake Linux Corporate Server Version4.0
Mandrakesoft ≫ Mandrake Linux Corporate Server Version4.0 Editionx86_64
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 7.49% | 0.909 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.5 | 6.8 | 10 |
AV:N/AC:M/Au:S/C:C/I:C/A:C
|