Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2004-0914


Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file. NOTE: it is highly likely that this candidate will be SPLIT into other candidates in the future, per CVE's content decisions.


Published

2005-01-10T05:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 10.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application lesstif lesstif 0.93 Yes
Application lesstif lesstif 0.93.12 Yes
Application lesstif lesstif 0.93.18 Yes
Application lesstif lesstif 0.93.34 Yes
Application lesstif lesstif 0.93.36 Yes
Application lesstif lesstif 0.93.40 Yes
Application lesstif lesstif 0.93.91 Yes
Application lesstif lesstif 0.93.94 Yes
Application lesstif lesstif 0.93.96 Yes
Application x.org x11r6 6.7.0 Yes
Application x.org x11r6 6.8 Yes
Application x.org x11r6 6.8.1 Yes
Application xfree86_project x11r6 3.3 Yes
Application xfree86_project x11r6 3.3.2 Yes
Application xfree86_project x11r6 3.3.3 Yes
Application xfree86_project x11r6 3.3.4 Yes
Application xfree86_project x11r6 3.3.5 Yes
Application xfree86_project x11r6 3.3.6 Yes
Application xfree86_project x11r6 4.0 Yes
Application xfree86_project x11r6 4.0.1 Yes
Application xfree86_project x11r6 4.0.2.11 Yes
Application xfree86_project x11r6 4.0.3 Yes
Application xfree86_project x11r6 4.1.0 Yes
Application xfree86_project x11r6 4.1.11 Yes
Application xfree86_project x11r6 4.1.12 Yes
Application xfree86_project x11r6 4.2.0 Yes
Application xfree86_project x11r6 4.2.1 Yes
Application xfree86_project x11r6 4.2.1 Yes
Application xfree86_project x11r6 4.3.0 Yes
Operating System gentoo linux * Yes
Operating System redhat fedora_core core_2.0 Yes
Operating System redhat fedora_core core_3.0 Yes
Operating System suse suse_linux 1.0 Yes
Operating System suse suse_linux 8 Yes
Operating System suse suse_linux 8.1 Yes
Operating System suse suse_linux 8.2 Yes
Operating System suse suse_linux 9.0 Yes
Operating System suse suse_linux 9.0 Yes
Operating System suse suse_linux 9.1 Yes
Operating System suse suse_linux 9.2 Yes

References