X

Libxfont

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 01.12.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.

Exploit
  • EPSS 0.51%
  • Veröffentlicht 18.08.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A single byte overflow in catalogue.c in X.Org libXfont 1.3.1 allows remote attackers to have unspecified impact.

  • EPSS 2.44%
  • Veröffentlicht 20.03.2015 14:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly perform type conversion for metrics values, which allows remote authenticated users to cause a denial of service (out-of-bounds...

  • EPSS 1.71%
  • Veröffentlicht 20.03.2015 14:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated users to cause a denial of service (NULL pointer der...

  • EPSS 1.76%
  • Veröffentlicht 20.03.2015 14:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The bdfReadProperties function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 allows remote authenticated users to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a (1) negat...

  • EPSS 0.11%
  • Veröffentlicht 15.05.2014 14:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a directory with a large fonts.dir or fonts.alias file ...

  • EPSS 2.11%
  • Veröffentlicht 15.05.2014 14:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple buffer overflows in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs protocol reply to the (1) _fs_recv_conn_setup, (2) fs_read_open_font, (3) fs_read_query_info, ...

  • EPSS 2.43%
  • Veröffentlicht 15.05.2014 14:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple integer overflows in the (1) fs_get_reply, (2) fs_alloc_glyphs, and (3) fs_read_extent_info functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs reply, wh...

Exploit
  • EPSS 8.1%
  • Veröffentlicht 09.01.2014 18:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character nam...

  • EPSS 6.12%
  • Veröffentlicht 19.08.2011 17:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x...