Skip to main content

Vendor archive

xfree86_project CVEs

Beta · best-effort

37 CVEs tagged to vendor xfree86_project6 Critical, 19 High, 10 Medium, 2 Low, 0 Unrated.

CVE-2007-5760

Published Jan 18, 2008

Array index error in the XFree86-Misc extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via a PassMessage request containing a l…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-1351

Published Apr 6, 2007

Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execu…

CVSS 8.5 · High

CVE-2006-6101

Published Dec 31, 2006

Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary co…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6102

Published Dec 31, 2006

Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6103

Published Dec 31, 2006

Integer overflow in the ProcDbeSwapBuffers function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code v…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3739

Published Sep 13, 2006

Integer overflow in the CIDAFM function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted Adobe Font Metrics (AFM) files with a modified…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3740

Published Sep 13, 2006

Integer overflow in the scan_cidfont function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted (1) CMap and (2) CIDFont font data with…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2495

Published Sep 15, 2005

Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0419

Published Aug 18, 2004

XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended rest…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0093

Published Mar 15, 2004

XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Ren…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0094

Published Mar 15, 2004

Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Renderin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0083

Published Mar 3, 2004

Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias)…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0084

Published Mar 3, 2004

Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitr…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0106

Published Mar 3, 2004

Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0730

Published Oct 20, 2003

Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1409

Published Jul 24, 2003

dexconf in XFree86 Xserver 4.1.0-2 creates the /dev/dri directory with insecure permissions (666), which allows local users to replace or create files in the root file system.

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-1472

Published Mar 3, 2003

Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid programs, allows local users to gain root privileges via a modified LD_PRELOAD environme…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1510

Published Mar 3, 2003

xdm, with the authComplain variable set to false, allows arbitrary attackers to connect to the X server if the xdm auth directory does not exist.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0063

Published Mar 3, 2003

The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0071

Published Mar 3, 2003

The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 37 CVEsPage 1 of 2