7.5

CVE-2014-0211

Multiple integer overflows in the (1) fs_get_reply, (2) fs_alloc_glyphs, and (3) fs_read_extent_info functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs reply, which triggers a buffer overflow.

Data is provided by the National Vulnerability Database (NVD)
CanonicalUbuntu Linux Version10.04 Update- Editionlts
CanonicalUbuntu Linux Version12.04 Update- Editionlts
CanonicalUbuntu Linux Version12.10
CanonicalUbuntu Linux Version13.10
CanonicalUbuntu Linux Version14.04 SwEditionlts
XLibxfont Version <= 1.4.7
XLibxfont Version1.2.3
XLibxfont Version1.2.4
XLibxfont Version1.2.5
XLibxfont Version1.2.6
XLibxfont Version1.2.7
XLibxfont Version1.2.8
XLibxfont Version1.2.9
XLibxfont Version1.3.0
XLibxfont Version1.3.1
XLibxfont Version1.3.2
XLibxfont Version1.3.3
XLibxfont Version1.3.4
XLibxfont Version1.4.0
XLibxfont Version1.4.1
XLibxfont Version1.4.2
XLibxfont Version1.4.3
XLibxfont Version1.4.4
XLibxfont Version1.4.5
XLibxfont Version1.4.6
XLibxfont Version1.4.99
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.43% 0.845
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P