Lucene search

K
cve[email protected]CVE-2007-6427
HistoryJan 18, 2008 - 11:00 p.m.

CVE-2007-6427

2008-01-1823:00:00
CWE-787
web.nvd.nist.gov
75
x.org xserver
arbitrary code execution
byte swapping
cve-2007-6427
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

9.8 High

AI Score

Confidence

High

0.034 Low

EPSS

Percentile

91.5%

The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.

Affected configurations

NVD
Node
x.orgx_serverRange<1.4.1
Node
canonicalubuntu_linuxMatch6.06lts
OR
canonicalubuntu_linuxMatch6.10
OR
canonicalubuntu_linuxMatch7.04
OR
canonicalubuntu_linuxMatch7.10
Node
debiandebian_linuxMatch3.1
OR
debiandebian_linuxMatch4.0
Node
applemac_os_xRange<10.4.11
OR
applemac_os_xRange10.5.010.5.2
Node
fedoraprojectfedoraMatch7
OR
fedoraprojectfedoraMatch8
Node
opensuseopensuseMatch10.2
OR
opensuseopensuseMatch10.3
OR
suselinuxMatch10.1
OR
suselinux_enterprise_desktopMatch9
OR
suselinux_enterprise_desktopMatch10-
OR
suselinux_enterprise_desktopMatch10sp1
OR
suselinux_enterprise_serverMatch8
OR
suselinux_enterprise_serverMatch9
OR
suselinux_enterprise_serverMatch10sp1
OR
suselinux_enterprise_software_development_kitMatch10sp1
OR
suseopen_enterprise_serverMatch-
CPENameOperatorVersion
x.org:x_serverx.org x serverlt1.4.1

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

9.8 High

AI Score

Confidence

High

0.034 Low

EPSS

Percentile

91.5%