Show filters
28 Total Results
Displaying 21-28 of 28
Sort by:
Attacker Value
Unknown

CVE-2006-4447

Disclosure Date: August 30, 2006 (last updated October 04, 2023)
X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit.
0
Attacker Value
Unknown

CVE-2005-3178

Disclosure Date: October 07, 2005 (last updated February 22, 2025)
Buffer overflow in xloadimage 4.1 and earlier, and xli, might allow user-assisted attackers to execute arbitrary code via a long title name in a NIFF file, which triggers the overflow during (1) zoom, (2) reduce, or (3) rotate operations.
0
Attacker Value
Unknown

CVE-2005-0639

Disclosure Date: March 02, 2005 (last updated February 22, 2025)
Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be related to integer overflows in PPM files.
0
Attacker Value
Unknown

CVE-2005-0638

Disclosure Date: March 02, 2005 (last updated February 22, 2025)
xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.
0
Attacker Value
Unknown

CVE-2004-0255

Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.
0
Attacker Value
Unknown

CVE-2004-0287

Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow.
0
Attacker Value
Unknown

CVE-2001-0775

Disclosure Date: October 18, 2001 (last updated February 22, 2025)
Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via a FACES format image containing a long (1) Firstname or (2) Lastname field.
0
Attacker Value
Unknown

CVE-2000-0976

Disclosure Date: December 19, 2000 (last updated February 22, 2025)
Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter.
0