[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244411

 
 

909

 
 

193363

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-8094Date: (C)2014-12-10   (M)2023-12-22


Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.5
Exploit Score: 8.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: SINGLE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECUNIA-61947
SECUNIA-62292
BID-71601
DSA-3095
GLSA-201504-06
MDVSA-2015:119
http://advisories.mageia.org/MGASA-2014-0532.html
http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/

CWE    1
CWE-190
OVAL    9
oval:org.secpod.oval:def:52366
oval:org.secpod.oval:def:1500801
oval:org.secpod.oval:def:1200028
oval:org.secpod.oval:def:203511
...

© SecPod Technologies