Lucene search

K
nvd[email protected]NVD:CVE-2013-4396
HistoryOct 10, 2013 - 10:55 a.m.

CVE-2013-4396

2013-10-1010:55:06
CWE-399
web.nvd.nist.gov

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.029 Low

EPSS

Percentile

90.8%

Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure.

Affected configurations

NVD
Node
xx.org_x11Match6.0
OR
xx.org_x11Match6.1
OR
xx.org_x11Match6.3
OR
xx.org_x11Match6.4
OR
xx.org_x11Match6.5.1
OR
xx.org_x11Match6.6
OR
xx.org_x11Match6.7
OR
xx.org_x11Match6.8
OR
xx.org_x11Match6.8.1
OR
xx.org_x11Match6.8.2
OR
xx.org_x11Match6.9.0
OR
xx.org_x11Match7.0
OR
xx.org_x11Match7.1
OR
xx.org_x11Match7.2
OR
xx.org_x11Match7.3
OR
xx.org_x11Match7.4
OR
xx.org_x11Match7.5
OR
xx.org_x11Match7.5rc1
OR
xx.org_x11Match7.6
OR
xx.org_x11Match7.6rc1
OR
xx.org_x11Match7.7
OR
xx.org_x11Match7.7rc1

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.029 Low

EPSS

Percentile

90.8%