CVE-2003-0730Improper Restriction of Operations within the Bounds of a Memory Buffer in Project X11r6

5 documents5 sources
Severity
7.5HIGHNVD
EPSS
5.7%
top 9.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 20
Latest updateMay 3

Description

Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-based buffer overflow attacks.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDxfree86_project/x11r64.2.1, 4.3.0+1

Also affects: Netbsd 1.5, 1.5.1, 1.5.2, 1.5.3, 1.6, 1.6.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f7q7-fmv4-99cj: Multiple integer overflows in the font libraries for XFree86 42022-05-03
CVEList
CVE-2003-0730: Multiple integer overflows in the font libraries for XFree86 42003-09-03

📋Vendor Advisories

1
Red Hat
security flaw2003-08-30

💬Community

1
Bugzilla
CVE-2003-0730 security flaw2018-08-16
CVE-2003-0730 — Xfree86 Project X11r6 vulnerability | cvebase