Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-1483

21
FAUCET Score

CVE-2008-1483 describes a local privilege escalation vulnerability in OpenSSH 4.3p2 and potentially other versions, affecting OpenBSD and OpenSSH products. It allows local users to hijack forwarded X connections by manipulating the DISPLAY environment variable, even if another process is using the associated port. The vulnerability has a CVSS score of 6.9, indicating high severity with local access, medium attack complexity, and complete confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, no known exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
4.3p2CPE matchmatch criteria
cpe:2.3:a:openbsd:openssh:4.3p2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.9MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
3.4
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.35%
Probability of exploitation in next 30 days
EPSS Percentile
27.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0035 is in the 33rd percentile among its peer group of 1,595 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

latchsetpatch availablevia llm_extracted
Fixed in: 5.0
View patch
nodejspatch availablevia llm_extracted
Fixed in: 5.0
View patch
openldappatch availablevia llm_extracted
Fixed in: 5.0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: openssh-0:3.9p1-8.RHEL4.9
View patch
traefikpatch availablevia llm_extracted
Fixed in: 5.0
View patch

Vendor Advisories (5)

openldapllm-openldap-3089c417e33deaa4

X11 hijacking attack.

Apr 3, 2008
traefikllm-traefik-e5ea41331e0e3035

X11 hijacking attack

Apr 3, 2008
nodejsllm-nodejs-59fc08e3e60653cd

An X11 hijacking attack (CVE-2008-1483) affected OpenSSH versions prior to 5.0.

Apr 3, 2008
latchsetllm-latchset-3ecb45e00999c0ac

X11 hijacking attack.

Apr 3, 2008
redhatCVE-2008-1483Low

openssh may set DISPLAY even if it's unable to listen on respective port

Jan 8, 2008

References

ftp.netbsd.org / pub/NetBSD/security/advisories/NetBSD-SA2008-005.txt.asc
aix.software.ibm.com / aix/efixes/security/ssh_advisory.asc
bugs.debian.org / cgi-bin/bugreport.cgi
h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
lists.apple.com / archives/security-announce//2008/Sep/msg00005.html
lists.opensuse.org / opensuse-security-announce/2008-04/msg00007.html
secunia.com / advisories/29522
Vendor Advisory
secunia.com / advisories/29537
Vendor Advisory
secunia.com / advisories/29554
Vendor Advisory
secunia.com / advisories/29626
Vendor Advisory
secunia.com / advisories/29676
Vendor Advisory
secunia.com / advisories/29683
Vendor Advisory
secunia.com / advisories/29686
Vendor Advisory
secunia.com / advisories/29721
Vendor Advisory
secunia.com / advisories/29735
Vendor Advisory
secunia.com / advisories/29873
Vendor Advisory
secunia.com / advisories/29939
Vendor Advisory
secunia.com / advisories/30086
Vendor Advisory
secunia.com / advisories/30230
Vendor Advisory
secunia.com / advisories/30249
Vendor Advisory
secunia.com / advisories/30347
secunia.com / advisories/30361
Vendor Advisory
secunia.com / advisories/31531
Vendor Advisory
secunia.com / advisories/31882
Vendor Advisory
security.freebsd.org / advisories/FreeBSD-SA-08:05.openssh.asc
exchange.xforce.ibmcloud.com / vulnerabilities/41438
issues.rpath.com / browse/RPL-2397
sourceforge.net / project/shownotes.php
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6085
sunsolve.sun.com / search/document.do
sunsolve.sun.com / search/document.do
support.attachmate.com / techdocs/2374.html
support.avaya.com / elmodocs2/security/ASA-2008-205.htm
usn.ubuntu.com / 597-1
tools.cisco.com / security/center/content/CiscoSecurityNotice/CVE-2008-1483
wiki.rpath.com / wiki/Advisories:rPSA-2008-0120
debian.org / security/2008/dsa-1576
gentoo.org / security/en/glsa/glsa-200804-03.xml
globus.org / mail_archive/security-announce/2008/04/msg00000.html
mandriva.com / security/advisories
securityfocus.com / archive/1/490054/100/0/threaded
securityfocus.com / bid/28444
securitytracker.com / id
slackware.org / security/viewer.php
us-cert.gov / cas/techalerts/TA08-260A.html
US Government Resource
vupen.com / english/advisories/2008/0994/references
vupen.com / english/advisories/2008/1123/references
vupen.com / english/advisories/2008/1124/references
vupen.com / english/advisories/2008/1448/references
vupen.com / english/advisories/2008/1526/references
vupen.com / english/advisories/2008/1624/references
vupen.com / english/advisories/2008/1630/references
vupen.com / english/advisories/2008/2396
vupen.com / english/advisories/2008/2584