6.5

CVE-2013-4396

Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure.

Data is provided by the National Vulnerability Database (NVD)
XX.Org X11 Version6.0
XX.Org X11 Version6.1
XX.Org X11 Version6.3
XX.Org X11 Version6.4
XX.Org X11 Version6.5.1
XX.Org X11 Version6.6
XX.Org X11 Version6.7
XX.Org X11 Version6.8
XX.Org X11 Version6.8.1
XX.Org X11 Version6.8.2
XX.Org X11 Version6.9.0
XX.Org X11 Version7.0
XX.Org X11 Version7.1
XX.Org X11 Version7.2
XX.Org X11 Version7.3
XX.Org X11 Version7.4
XX.Org X11 Version7.5
XX.Org X11 Version7.5 Updaterc1
XX.Org X11 Version7.6
XX.Org X11 Version7.6 Updaterc1
XX.Org X11 Version7.7
XX.Org X11 Version7.7 Updaterc1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.57% 0.798
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P