6.5

CVE-2013-4396

Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
XX.Org X11 Version6.0
XX.Org X11 Version6.1
XX.Org X11 Version6.3
XX.Org X11 Version6.4
XX.Org X11 Version6.5.1
XX.Org X11 Version6.6
XX.Org X11 Version6.7
XX.Org X11 Version6.8
XX.Org X11 Version6.8.1
XX.Org X11 Version6.8.2
XX.Org X11 Version6.9.0
XX.Org X11 Version7.0
XX.Org X11 Version7.1
XX.Org X11 Version7.2
XX.Org X11 Version7.3
XX.Org X11 Version7.4
XX.Org X11 Version7.5
XX.Org X11 Version7.5 Updaterc1
XX.Org X11 Version7.6
XX.Org X11 Version7.6 Updaterc1
XX.Org X11 Version7.7
XX.Org X11 Version7.7 Updaterc1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.57% 0.798
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P