CVE-2014-8101 describes an out-of-bounds read or write vulnerability in the RandR extension of XFree86, X.Org X Window System, and X.Org Server versions prior to 1.16.3. An authenticated remote attacker can exploit this by sending crafted length or index values to specific functions, potentially leading to a denial of service or arbitrary code execution. This vulnerability has a CVSS score of 6.5 (medium severity), indicating it can be exploited remotely with low attack complexity by an authenticated user, potentially impacting confidentiality, integrity, and availability. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community attention and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.0CPE matchmatch criteria | cpe:2.3:a:x.org:xfree86:4.2.0:*:*:*:*:*:*:* | ||
<= 1.16.2.99.901CPE matchmatch criteria | cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:* | ||
6.7CPE matchmatch criteria | cpe:2.3:a:x.org:x11:6.7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.