10
CVSSv2

CVE-2014-2977

Published: 11/06/2014 Updated: 30/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers a stack-based buffer overflow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 13.1

suse linux enterprise software development kit 12

suse suse linux enterprise server 12

suse linux enterprise desktop 12

opensuse opensuse 13.2

suse linux enterprise workstation extension 12

directfb directfb 1.4.13