Unrated severityNVD Advisory· Published May 2, 2007· Updated Apr 23, 2026
CVE-2007-2437
CVE-2007-2437
Description
The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to cause a denial of service (daemon crash) via crafted values to the (1) XRenderCompositeTrapezoids and (2) XRenderAddTraps functions, which trigger a divide-by-zero error.
Affected products
4cpe:2.3:a:x.org:x_window_system:7.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:x.org:x_window_system:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:x.org:x_window_system:7.1:*:*:*:*:*:*:*
- cpe:2.3:a:x.org:x_window_system:7.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.rapid7.com/advisories/R7-0027.jspnvdPatch
- www.securitytracker.com/idnvdPatch
- osvdb.org/34905nvd
- secunia.com/advisories/25121nvd
- sunsolve.sun.com/search/document.donvd
- sunsolve.sun.com/search/document.donvd
- www.securityfocus.com/bid/23741nvd
- www.vupen.com/english/advisories/2007/1601nvd
- www.vupen.com/english/advisories/2007/1658nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/33976nvd
News mentions
0No linked articles in our index yet.