Lucene search

K
cve[email protected]CVE-2014-8091
HistoryDec 10, 2014 - 3:59 p.m.

CVE-2014-8091

2014-12-1015:59:02
web.nvd.nist.gov
56
cve-2014-8091
x.org x window system
x11
x.org server
x11r5
secure rpc
denial of service

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

7.2 High

AI Score

Confidence

High

0.063 Low

EPSS

Percentile

93.7%

X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver and xorg-server) before 1.16.3, when using SUN-DES-1 (Secure RPC) authentication credentials, does not check the return value of a malloc call, which allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a crafted connection request.

Affected configurations

NVD
Node
x.orgxorg-serverRange1.16.2
Node
x.orgx11Match5.0

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

7.2 High

AI Score

Confidence

High

0.063 Low

EPSS

Percentile

93.7%