« Volver al listado

CVE-2007-2455

Estado: ModificadaMedia (6.1)—

Parallels allows local users to cause a denial of service (virtual machine abort) via (1) certain INT instructions, as demonstrated by INT 0xAA; (2) an IRET instruction when an invalid address is at the top of the stack; (3) a malformed MOVNTI instruction, as demonstrated by using a register as a destination; or a write operation to (4) SEGR6 or (5) SEGR7.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-2455",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.1,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:L/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.5,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-05-02T17:19:00.000",
  "references": [
    {
      "url": "http://osvdb.org/41164",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/41165",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/41166",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/41167",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://taviso.decsystem.org/virtsec.pdf",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/41164",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/41165",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/41166",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/41167",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://taviso.decsystem.org/virtsec.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Parallels allows local users to cause a denial of service (virtual machine abort) via (1) certain INT instructions, as demonstrated by INT 0xAA; (2) an IRET instruction when an invalid address is at the top of the stack; (3) a malformed MOVNTI instruction, as demonstrated by using a register as a destination; or a write operation to (4) SEGR6 or (5) SEGR7."
    },
    {
      "lang": "es",
      "value": "Parallels permite a usuarios locales provocar una denegación de servicio (detención de máquina virtual) mediante (1) determinadas instruciones INT, como se ha demostrado con INT 0xAA; (2) una instrucción IRET cuando una dirección inválida está en la posición superior de la pila; (3) una instrucción MOVNTI mal formada, como se ha demostrado utilizando un registro como destino; o una operación de escritura a (4) SEGR6 o (5) SEGR7."
    }
  ],
  "lastModified": "2026-06-16T22:39:38.563",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:parallels:parallels_desktop:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3AC6A933-31CC-4966-A87E-B8AFB2479081"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}