VDB
CVE-2008-1944
CVE-2008-1944
PUBLISHED
CVSS 7.199999809265137 HIGH
Buffer overflow in the backend framebuffer of XenSource Xen Para-Virtualized Framebuffer (PVFB) Message 3.0 through 3.0.3 allows local users to cause a denial of service (SDL crash) and possibly execute arbitrary code via "bogus screen updates," related to missing validation of the "format of messages."
EPSS 0.08% · 22.7th percentile
Risk Scores
CVSS 2.0
7.199999809265137
EPSS Score
0.08%
22.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| xensource | xen | 3.0, 3.0.3 |
Exploit Intelligence
- RHSA-2008:0194 (circl)
- 1020009 (circl)
- xen-pvfb-message-dos(42388) (circl)
- 29963 (circl)
- https://bugzilla.redhat.com/show_bug.cgi?id=443390 (circl)
- oval:org.mitre.oval:def:10868 (circl)
- 29186 (circl)
Timeline
- May 14, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- RHSA-2008:0194 vendor-advisory
- 1020009 vdb
- xen-pvfb-message-dos(42388) vdb
- 29963 third-party-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=443390 url
- oval:org.mitre.oval:def:10868 vdb
- 29186 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2008-1944 advisory