cbcvebase.
CVE-2007-6427
published 2008-01-18

CVE-2007-6427: The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap…

PriorityP344critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.28%
90.0th percentile
The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.

Affected

25 ranges
VendorProductVersion rangeFixed in
applemac_os_x< 10.4.1110.4.11
applemac_os_x>= 10.5.0 < 10.5.210.5.2
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianxorg-server< xorg-server 2:1.4.1~git20080105-2 (bookworm)xorg-server 2:1.4.1~git20080105-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
opensuseopensuse
opensuseopensuse
suselinux
suselinux_enterprise_desktop
suselinux_enterprise_desktop
suselinux_enterprise_server
suselinux_enterprise_server
suselinux_enterprise_server
suselinux_enterprise_software_development_kit
x.orgx_server< 1.4.11.4.1
x.orgxorg-server>= 0 < 2:1.4.1~git20080105-22:1.4.1~git20080105-2
x.orgxorg-server>= 0 < 2:1.4.1~git20080105-22:1.4.1~git20080105-2
x.orgxorg-server>= 0 < 2:1.4.1~git20080105-22:1.4.1~git20080105-2
x.orgxorg-server>= 0 < 2:1.4.1~git20080105-22:1.4.1~git20080105-2

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.5HIGH
vendor_ubuntu9.3CRITICAL
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.