cbcvebase.
CVE-2007-1003
published 2007-04-06

CVE-2007-1003: Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other…

PriorityP340critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
5.25%
91.7th percentile
Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, allows remote authenticated users to execute arbitrary code via a large expression, which results in memory corruption.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianxorg-server< xorg-server 2:1.1.1-21 (bookworm)xorg-server 2:1.1.1-21 (bookworm)
x.orgx11
x.orgxorg-server>= 0 < 2:1.1.1-212:1.1.1-21
x.orgxorg-server>= 0 < 2:1.1.1-212:1.1.1-21
x.orgxorg-server>= 0 < 2:1.1.1-212:1.1.1-21
x.orgxorg-server>= 0 < 2:1.1.1-212:1.1.1-21

CVSS provenance

nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv9.0CRITICAL
vendor_debian9.0MEDIUM
vendor_redhat9.0CRITICAL
vendor_ubuntu9.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.