7.2
CVE-2008-1944
- EPSS 0.08%
- Published 14.05.2008 18:20:00
- Last modified 09.04.2025 00:30:58
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
Buffer overflow in the backend framebuffer of XenSource Xen Para-Virtualized Framebuffer (PVFB) Message 3.0 through 3.0.3 allows local users to cause a denial of service (SDL crash) and possibly execute arbitrary code via "bogus screen updates," related to missing validation of the "format of messages."
Data is provided by the National Vulnerability Database (NVD)
Xensource ≫ Xen Version3.0
Redhat ≫ Desktop Version5
Redhat ≫ Enterprise Linux Version5.0 Editionclient
Redhat ≫ Enterprise Linux Version5.0 Editionserver
Redhat ≫ Virtualization Server Version5
Redhat ≫ Enterprise Linux Version5.0 Editionclient
Redhat ≫ Enterprise Linux Version5.0 Editionserver
Redhat ≫ Virtualization Server Version5
Xensource ≫ Xen Version3.0.3
Redhat ≫ Desktop Version5
Redhat ≫ Enterprise Linux Version5.0 Editionclient
Redhat ≫ Enterprise Linux Version5.0 Editionserver
Redhat ≫ Virtualization Server Version5
Redhat ≫ Enterprise Linux Version5.0 Editionclient
Redhat ≫ Enterprise Linux Version5.0 Editionserver
Redhat ≫ Virtualization Server Version5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.08% | 0.197 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.