Vulnerabilities > Xfree86 Project > X11R6 > High

DATE CVE VULNERABILITY TITLE RISK
2007-04-06 CVE-2007-1351 Numeric Errors vulnerability in multiple products
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.
8.5
2005-03-02 CVE-2005-0605 Integer Overflow vulnerability in libXPM Bitmap_unit
scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.
7.5
2004-10-20 CVE-2004-0688 Remote Buffer Overflow vulnerability in libXpm Image Decoding
Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.
network
low complexity
x-org xfree86-project openbsd suse
7.5
2004-03-15 CVE-2004-0094 Buffer Overflow vulnerability in XFree86 Direct Rendering Infrastructure
Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Rendering Infrastructure (DRI).
network
low complexity
xfree86-project
7.5
2004-03-15 CVE-2004-0093 Buffer Overflow vulnerability in XFree86 Direct Rendering Infrastructure
XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Rendering Infrastructure (DRI).
network
low complexity
xfree86-project
7.5
2004-03-03 CVE-2004-0106 Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.
local
low complexity
xfree86-project openbsd
7.2
2003-10-20 CVE-2003-0730 Integer Overflow vulnerability in XFree86
Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-based buffer overflow attacks.
network
low complexity
xfree86-project netbsd
7.5
2003-03-03 CVE-2002-1472 Local Privilege Escalation vulnerability in Xfree86 Project X11R6 4.1.0/4.2.0
Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid programs, allows local users to gain root privileges via a modified LD_PRELOAD environment variable that points to a malicious module.
local
low complexity
xfree86-project
7.2
2002-12-11 CVE-2002-1317 Remote Buffer Overrun vulnerability in Multiple Vendor X Font Server
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.
network
low complexity
xfree86-project sgi hp sun
7.5
2001-09-22 CVE-2001-0955 Denial of Service vulnerability in Xfree86 Project X11R6 4.0/4.0.1/4.0.3
Buffer overflow in fbglyph.c in XFree86 before 4.2.0, related to glyph clipping for large origins, allows attackers to cause a denial of service and possibly gain privileges via a large number of characters, possibly through the web page search form of KDE Konqueror or from an xterm command with a long title.
local
low complexity
xfree86-project
7.2