3.6

CVE-2015-3164

The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpensuseOpensuse Version13.2
X.OrgX Server Version1.16.0
X.OrgX Server Version1.16.1
X.OrgX Server Version1.16.1.901
X.OrgX Server Version1.16.2
X.OrgX Server Version1.16.2.901
X.OrgX Server Version1.16.3
X.OrgX Server Version1.17.0
X.OrgXorg-server Version1.16.4
X.OrgXorg-server Version1.16.99.901
X.OrgXorg-server Version1.16.99.902
X.OrgXorg-server Version1.17.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.204
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.6 3.9 4.9
AV:L/AC:L/Au:N/C:P/I:P/A:N