Vulnerabilities
Vulnerable Software
X.org:  Security Vulnerabilities
The XClientMessageEvent struct used in certain components of X.Org 6.8.2 and earlier, possibly including (1) the X server and (2) Xlib, uses a "long" specifier for elements of the l array, which results in inconsistent sizes in the struct on 32-bit versus 64-bit platforms, and might allow attackers to cause a denial of service (application crash) and possibly conduct other attacks.
CVSS Score
5.0
EPSS Score
0.011
Published
2006-01-13
scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.
CVSS Score
7.5
EPSS Score
0.045
Published
2005-03-02
Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file. NOTE: it is highly likely that this candidate will be SPLIT into other candidates in the future, per CVE's content decisions.
CVSS Score
10.0
EPSS Score
0.087
Published
2005-01-10
Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file.
CVSS Score
7.5
EPSS Score
0.081
Published
2004-10-20
Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.
CVSS Score
7.5
EPSS Score
0.072
Published
2004-10-20
XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.
CVSS Score
7.5
EPSS Score
0.025
Published
2004-08-18
Race condition in xterm allows local users to modify arbitrary files via the logging option.
CVSS Score
6.2
EPSS Score
0.003
Published
1997-09-19
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
CVSS Score
10.0
EPSS Score
0.208
Published
1997-07-01


Contact Us

Shodan ® - All rights reserved