VDB
CVE-2008-1944
CVE-2008-1944
PUBLISHED
CVSS 7.199999809265137 HIGH
Buffer overflow in the backend framebuffer of XenSource Xen Para-Virtualized Framebuffer (PVFB) Message 3.0 through 3.0.3 allows local users to cause a denial of service (SDL crash) and possibly execute arbitrary code via "bogus screen updates," related to missing validation of the "format of messages."
EPSS 0.47% · 38.7th percentile
Risk Scores
CVSS 2.0
7.199999809265137
EPSS Score
0.47%
38.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| xensource | xen | 3.0, 3.0.3 |
Timeline
- May 14, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 1, 2022 CVE Updated
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 12, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 6, 2023 EPSS Score
References
- xen-pvfb-message-dos(42388) vdb
- 29963 third-party-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=443390 url
- oval:org.mitre.oval:def:10868 vdb
- RHSA-2008:0194 vendor-advisory
- 1020009 vdb
- 29186 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2008-1944 advisory