7.5
CVE-2008-5903
- EPSS 3.16%
- Veröffentlicht 15.01.2009 17:30:00
- Zuletzt bearbeitet 16.06.2026 23:01:11
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Array index error in the xrdp_bitmap_def_proc function in xrdp/funcs.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via vectors that manipulate the value of the edit_pos structure member.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.16% | 0.863 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html
http://openwall.com/lists/oss-security/2009/01/12/3
http://packetstormsecurity.org/0812-advisories/VA_VD_87_08_XRDP.pdf
http://www.securityfocus.com/bid/33371
https://exchange.xforce.ibmcloud.com/vulnerabilities/48093