5.9
CVE-2015-8316
- EPSS 0.59%
- Veröffentlicht 06.09.2017 21:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle security@debian.org
- CVE-Watchlists
- Unerledigt
Array index error in LightDM (aka Light Display Manager) 1.14.3, 1.16.x before 1.16.6 when the XDMCP server is enabled allows remote attackers to cause a denial of service (process crash) via an XDMCP request packet with no address.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lightdm Project ≫ Lightdm Version1.14.3
Lightdm Project ≫ Lightdm Version1.16
Lightdm Project ≫ Lightdm Version1.16.1
Lightdm Project ≫ Lightdm Version1.16.2
Lightdm Project ≫ Lightdm Version1.16.3
Lightdm Project ≫ Lightdm Version1.16.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.59% | 0.666 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
CWE-129 Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.