7.2
CVE-2008-1944
- EPSS 0.08%
- Veröffentlicht 14.05.2008 18:20:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
Buffer overflow in the backend framebuffer of XenSource Xen Para-Virtualized Framebuffer (PVFB) Message 3.0 through 3.0.3 allows local users to cause a denial of service (SDL crash) and possibly execute arbitrary code via "bogus screen updates," related to missing validation of the "format of messages."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xensource ≫ Xen Version3.0
Redhat ≫ Desktop Version5
Redhat ≫ Enterprise Linux Version5.0 Editionclient
Redhat ≫ Enterprise Linux Version5.0 Editionserver
Redhat ≫ Virtualization Server Version5
Redhat ≫ Enterprise Linux Version5.0 Editionclient
Redhat ≫ Enterprise Linux Version5.0 Editionserver
Redhat ≫ Virtualization Server Version5
Xensource ≫ Xen Version3.0.3
Redhat ≫ Desktop Version5
Redhat ≫ Enterprise Linux Version5.0 Editionclient
Redhat ≫ Enterprise Linux Version5.0 Editionserver
Redhat ≫ Virtualization Server Version5
Redhat ≫ Enterprise Linux Version5.0 Editionclient
Redhat ≫ Enterprise Linux Version5.0 Editionserver
Redhat ≫ Virtualization Server Version5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.197 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.