// For flags

CVE-2007-5760

xorg: invalid array indexing in XFree86-Misc extension

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Array index error in the XFree86-Misc extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via a PassMessage request containing a large array index.

Error de índice de Array en la extensión XFree86-Misc de X.Org Xserver versiones anteriores a 1.4.1 permite a atacantes locales o remotos dependientes del contexto ejecutar código de su elección mediante una petición PassMessage conteniendo un índice de array largo.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-10-31 CVE Reserved
  • 2008-01-18 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-11-21 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (52)
URL Tag Source
http://bugs.gentoo.org/show_bug.cgi?id=204362 X_refsource_confirm
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=646 Third Party Advisory
http://secunia.com/advisories/28273 Third Party Advisory
http://secunia.com/advisories/28532 Third Party Advisory
http://secunia.com/advisories/28535 Third Party Advisory
http://secunia.com/advisories/28536 Third Party Advisory
http://secunia.com/advisories/28539 Third Party Advisory
http://secunia.com/advisories/28540 Third Party Advisory
http://secunia.com/advisories/28543 Third Party Advisory
http://secunia.com/advisories/28550 Third Party Advisory
http://secunia.com/advisories/28584 Third Party Advisory
http://secunia.com/advisories/28592 Third Party Advisory
http://secunia.com/advisories/28616 Third Party Advisory
http://secunia.com/advisories/28693 Third Party Advisory
http://secunia.com/advisories/28718 Third Party Advisory
http://secunia.com/advisories/28843 Third Party Advisory
http://secunia.com/advisories/28885 Third Party Advisory
http://secunia.com/advisories/28941 Third Party Advisory
http://secunia.com/advisories/29707 Third Party Advisory
http://secunia.com/advisories/30161 Third Party Advisory
http://securitytracker.com/id?1019232 Vdb Entry
http://support.avaya.com/elmodocs2/security/ASA-2008-039.htm X_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2008-078.htm X_refsource_confirm
http://www.securityfocus.com/archive/1/487335/100/0/threaded Mailing List
http://www.securityfocus.com/bid/27354 Vdb Entry
http://www.vupen.com/english/advisories/2008/0179 Vdb Entry
http://www.vupen.com/english/advisories/2008/0184 Vdb Entry
http://www.vupen.com/english/advisories/2008/0497/references Vdb Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/39766 Vdb Entry
https://issues.rpath.com/browse/RPL-2010 X_refsource_confirm
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11718 Signature
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
X.org
Search vendor "X.org"
Xserver
Search vendor "X.org" for product "Xserver"
<= 1.4
Search vendor "X.org" for product "Xserver" and version " <= 1.4"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
Xfree86-misc
Search vendor "Xfree86 Project" for product "Xfree86-misc"
*-
Affected