CVE-2014-8102 describes an out-of-bounds read or write vulnerability in the X.Org X Window System (X11R6.8.0 and X.Org Server before 1.16.3), specifically within the XFixes extension's SProcXFixesSelectSelectionInput function. This flaw allows remote authenticated users to trigger a denial of service or potentially execute arbitrary code through a crafted length value. With a CVSS score of 6.5, this vulnerability is rated as medium severity, indicating that an attacker can exploit it over a network with low complexity, potentially leading to partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting a low current threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.16.2.99.901CPE matchmatch criteria | cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:* | ||
6.8CPE matchmatch criteria | cpe:2.3:a:x.org:x11:6.8:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.