Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-6427

24
FAUCET Score

CVE-2007-6427 describes a critical vulnerability in the X.Org Xserver's XInput extension, affecting various Linux distributions and Apple systems. This flaw allows remote attackers to execute arbitrary code due to heap corruption and byte swapping issues within several functions. With a CVSS score of 9.3, it represents a high-severity risk with complete confidentiality, integrity, and availability impacts, requiring medium attack complexity. Despite its severity, there is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.4.1CPE matchmatch criteria
cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:*
6.06CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
6.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*
7.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*
7.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.3HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
4.28%
Probability of exploitation in next 30 days
EPSS Percentile
90.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0428 is in the 54th percentile among its peer group of 8,915 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: XFree86-0:4.1.0-86.EL
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: XFree86-0:4.3.0-126.EL
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: xorg-x11-0:6.8.2-1.EL.33.0.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: xorg-x11-server-0:1.1.1-48.26.el5_1.5
View patch

Vendor Advisories (1)

redhatCVE-2007-6427Important

xfree86: memory corruption via XInput extension

Jan 17, 2008

References

bugs.gentoo.org / show_bug.cgi
Issue TrackingPatchThird Party Advisory
docs.info.apple.com / article.html
Broken Link
h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
Broken Link
labs.idefense.com / intelligence/vulnerabilities/display.php
Broken Link
lists.apple.com / archives/security-announce/2008/Mar/msg00001.html
Mailing List
lists.freedesktop.org / archives/xorg/2008-January/031918.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2008-01/msg00004.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2008-02/msg00003.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2008-04/msg00005.html
Mailing ListThird Party Advisory
secunia.com / advisories/28273
Third Party Advisory
secunia.com / advisories/28532
Third Party Advisory
secunia.com / advisories/28535
Third Party Advisory
secunia.com / advisories/28536
Third Party Advisory
secunia.com / advisories/28539
Third Party Advisory
secunia.com / advisories/28540
Third Party Advisory
secunia.com / advisories/28542
Third Party Advisory
secunia.com / advisories/28543
Third Party Advisory
secunia.com / advisories/28550
Third Party Advisory
secunia.com / advisories/28584
Third Party Advisory
secunia.com / advisories/28592
Third Party Advisory
secunia.com / advisories/28616
Third Party Advisory
secunia.com / advisories/28693
Third Party Advisory
secunia.com / advisories/28718
Third Party Advisory
secunia.com / advisories/28838
Third Party Advisory
secunia.com / advisories/28843
Third Party Advisory
secunia.com / advisories/28885
Third Party Advisory
secunia.com / advisories/28941
Third Party Advisory
secunia.com / advisories/29139
Third Party Advisory
secunia.com / advisories/29420
Third Party Advisory
secunia.com / advisories/29622
Third Party Advisory
secunia.com / advisories/29707
Third Party Advisory
secunia.com / advisories/30161
Third Party Advisory
secunia.com / advisories/32545
Third Party Advisory
security.gentoo.org / glsa/glsa-200801-09.xml
Third Party Advisory
security.gentoo.org / glsa/glsa-200804-05.xml
Third Party Advisory
securitytracker.com / id
Third Party AdvisoryVDB Entry
exchange.xforce.ibmcloud.com / vulnerabilities/39759
Third Party AdvisoryVDB Entry
issues.rpath.com / browse/RPL-2010
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10372
Third Party Advisory
sunsolve.sun.com / search/document.do
Broken Link
sunsolve.sun.com / search/document.do
Broken Link
support.avaya.com / elmodocs2/security/ASA-2008-039.htm
Third Party Advisory
support.avaya.com / elmodocs2/security/ASA-2008-078.htm
Third Party Advisory
usn.ubuntu.com / 571-1
Third Party Advisory
redhat.com / archives/fedora-package-announce/2008-January/msg00641.html
Third Party Advisory
redhat.com / archives/fedora-package-announce/2008-January/msg00704.html
Third Party Advisory
www14.software.ibm.com / webapp/set2/subscriptions/ijhifoeblist
MitigationThird Party Advisory
debian.org / security/2008/dsa-1466
Third Party Advisory
gentoo.org / security/en/glsa/glsa-200805-07.xml
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
openbsd.org / errata41.html
Third Party Advisory
openbsd.org / errata42.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0029.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0030.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0031.html
Third Party Advisory
securityfocus.com / archive/1/487335/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/27336
PatchThird Party AdvisoryVDB Entry
securityfocus.com / bid/27351
Third Party AdvisoryVDB Entry
vupen.com / english/advisories/2008/0179
Third Party Advisory
vupen.com / english/advisories/2008/0184
Third Party Advisory
vupen.com / english/advisories/2008/0497/references
Third Party Advisory
vupen.com / english/advisories/2008/0703
Third Party Advisory
vupen.com / english/advisories/2008/0924/references
Third Party Advisory
vupen.com / english/advisories/2008/3000
Third Party Advisory