Show filters
28 Total Results
Displaying 21-28 of 28
Sort by:
Attacker Value
Unknown
CVE-2006-4447
Disclosure Date: August 30, 2006 (last updated October 04, 2023)
X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit.
0
Attacker Value
Unknown
CVE-2005-3178
Disclosure Date: October 07, 2005 (last updated February 22, 2025)
Buffer overflow in xloadimage 4.1 and earlier, and xli, might allow user-assisted attackers to execute arbitrary code via a long title name in a NIFF file, which triggers the overflow during (1) zoom, (2) reduce, or (3) rotate operations.
0
Attacker Value
Unknown
CVE-2005-0639
Disclosure Date: March 02, 2005 (last updated February 22, 2025)
Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be related to integer overflows in PPM files.
0
Attacker Value
Unknown
CVE-2005-0638
Disclosure Date: March 02, 2005 (last updated February 22, 2025)
xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.
0
Attacker Value
Unknown
CVE-2004-0255
Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.
0
Attacker Value
Unknown
CVE-2004-0287
Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow.
0
Attacker Value
Unknown
CVE-2001-0775
Disclosure Date: October 18, 2001 (last updated February 22, 2025)
Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via a FACES format image containing a long (1) Firstname or (2) Lastname field.
0
Attacker Value
Unknown
CVE-2000-0976
Disclosure Date: December 19, 2000 (last updated February 22, 2025)
Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter.
0