9.3

CVE-2007-6427

The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
X.OrgX Server Version < 1.4.1
CanonicalUbuntu Linux Version6.06 SwEditionlts
CanonicalUbuntu Linux Version6.10
CanonicalUbuntu Linux Version7.04
CanonicalUbuntu Linux Version7.10
DebianDebian Linux Version3.1
DebianDebian Linux Version4.0
ApplemacOS X Version < 10.4.11
ApplemacOS X Version >= 10.5.0 < 10.5.2
FedoraprojectFedora Version7
FedoraprojectFedora Version8
OpensuseOpensuse Version10.2
OpensuseOpensuse Version10.3
SuseLinux Version10.1
SuseLinux Enterprise Desktop Version10 Update-
SuseLinux Enterprise Desktop Version10 Updatesp1
SuseLinux Enterprise Server Version10 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.74% 0.869
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://bugs.gentoo.org/show_bug.cgi?id=204362
Patch
Third Party Advisory
Issue Tracking
http://securitytracker.com/id?1019232
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/27336
Patch
Third Party Advisory
VDB Entry
https://usn.ubuntu.com/571-1/
Third Party Advisory
http://www.securityfocus.com/bid/27351
Third Party Advisory
VDB Entry