Skip to main content

Vendor/product archive

xfree86_project / x11r6 CVEs

Beta · best-effort

26 CVEs tagged to xfree86_project / x11r64 Critical, 16 High, 5 Medium, 1 Low, 0 Unrated.

CVE-2007-1351

Published Apr 6, 2007

Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execu…

CVSS 8.5 · High

CVE-2004-0093

Published Mar 15, 2004

XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Ren…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0094

Published Mar 15, 2004

Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Renderin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0083

Published Mar 3, 2004

Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias)…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0084

Published Mar 3, 2004

Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitr…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0106

Published Mar 3, 2004

Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0730

Published Oct 20, 2003

Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1472

Published Mar 3, 2003

Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid programs, allows local users to gain root privileges via a modified LD_PRELOAD environme…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1510

Published Mar 3, 2003

xdm, with the authComplain variable set to false, allows arbitrary attackers to connect to the X server if the xdm auth directory does not exist.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0063

Published Mar 3, 2003

The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0071

Published Mar 3, 2003

The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-0955

Published Sep 22, 2001

Buffer overflow in fbglyph.c in XFree86 before 4.2.0, related to glyph clipping for large origins, allows attackers to cause a denial of service and possibly gain privileges via a…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1179

Published Jul 17, 2001

xman allows local users to gain privileges by modifying the MANPATH to point to a man page whose filename contains shell metacharacters.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1178

Published Jul 11, 2001

Buffer overflow in xman allows local users to gain privileges via a long MANPATH environment variable.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1086

Published Jul 4, 2001

XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0620

Published Jun 19, 2000

libX11 X library allows remote attackers to cause a denial of service via a resource mask of 0, which causes libX11 to go into an infinite loop.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0453

Published May 18, 2000

XFree86 3.3.x and 4.0 allows a user to cause a denial of service via a negative counter value in a malformed TCP packet that is sent to port 6000.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0285

Published Apr 16, 2000

Buffer overflow in XFree86 3.3.x allows local users to execute arbitrary commands via a long -xkbmap parameter.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2