cbcvebase.
CVE-2010-4819
published 2012-09-05

CVE-2010-4819: The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and…

PriorityP411low3.6CVSS 2.0
AVLACLAuNCPINAP
EPSS
0.34%
26.5th percentile
The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."

Affected

9 ranges
VendorProductVersion rangeFixed in
debianxorg-server< xorg-server 2:1.9.0.901-1 (bookworm)xorg-server 2:1.9.0.901-1 (bookworm)
x.orgxorg-server>= 0 < 2:1.9.0.901-12:1.9.0.901-1
x.orgxorg-server>= 0 < 2:1.9.0.901-12:1.9.0.901-1
x.orgxorg-server>= 0 < 2:1.9.0.901-12:1.9.0.901-1
x.orgxorg-server>= 0 < 2:1.9.0.901-12:1.9.0.901-1
xx.org-xserver<= 1.7.7
xx.org-xserver
xx.org-xserver
xx.org-xserver

CVSS provenance

nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
osv3.6LOW
vendor_ubuntu8.5HIGH
vendor_debian3.6LOW
vendor_redhat3.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.