X.Org Libxfont vulnerabilities
18 known vulnerabilities affecting x.org/libxfont.
Total CVEs
18
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH13MEDIUM2LOW1
Vulnerabilities
Page 1 of 1
CVE-2017-16611MEDIUMCVSS 5.5≥ 0, < 1:2.0.3-12017-12-01
CVE-2017-16611 [MEDIUM] CVE-2017-16611: In libXfont before 1
In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.
osv
CVE-2017-13720HIGHCVSS 7.1≤ 1.5.2v2.0.0+1 more2017-10-11
CVE-2017-13720 [HIGH] CWE-125 CVE-2017-13720: In the PatternMatch function in fontfile/fontdir.c in libXfont through 1.5.2 and 2.x before 2.0.2, a
In the PatternMatch function in fontfile/fontdir.c in libXfont through 1.5.2 and 2.x before 2.0.2, an attacker with access to an X connection can cause a buffer over-read during pattern matching of fonts, leading to information disclosure or a crash (denial of service). This occurs because '\0' characters are incorrectly skipped in situations involvin
nvdosv
CVE-2017-13722HIGHCVSS 7.1≤ 1.5.2v2.0.0+1 more2017-10-11
CVE-2017-13722 [HIGH] CWE-125 CVE-2017-13722: In the pcfGetProperties function in bitmap/pcfread.c in libXfont through 1.5.2 and 2.x before 2.0.2,
In the pcfGetProperties function in bitmap/pcfread.c in libXfont through 1.5.2 and 2.x before 2.0.2, a missing boundary check (for PCF files) could be used by local attackers authenticated to an Xserver for a buffer over-read, for information disclosure or a crash of the X server.
nvdosv
CVE-2007-5199CRITICALCVSS 9.8≥ 0, < 1:1.3.2-12017-08-18
CVE-2007-5199 [CRITICAL] CVE-2007-5199: A single byte overflow in catalogue
A single byte overflow in catalogue.c in X.Org libXfont 1.3.1 allows remote attackers to have unspecified impact.
osv
CVE-2015-1802HIGHCVSS 8.5≥ 0, < 1:1.5.1-12015-03-20
CVE-2015-1802 [HIGH] CVE-2015-1802: The bdfReadProperties function in bitmap/bdfread
The bdfReadProperties function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 allows remote authenticated users to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a (1) negative or (2) large property count in a BDF font file.
osv
CVE-2015-1803HIGHCVSS 8.5≥ 0, < 1:1.5.1-12015-03-20
CVE-2015-1803 [HIGH] CVE-2015-1803: The bdfReadCharacters function in bitmap/bdfread
The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a crafted BDF font file.
osv
CVE-2015-1804HIGHCVSS 8.5≥ 0, < 1:1.5.1-12015-03-20
CVE-2015-1804 [HIGH] CVE-2015-1804: The bdfReadCharacters function in bitmap/bdfread
The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly perform type conversion for metrics values, which allows remote authenticated users to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via a crafted BDF font file.
osv
CVE-2014-0211HIGHCVSS 7.5≥ 0, < 1:1.4.7-22014-05-15
CVE-2014-0211 [HIGH] CVE-2014-0211: Multiple integer overflows in the (1) fs_get_reply, (2) fs_alloc_glyphs, and (3) fs_read_extent_info functions in X
Multiple integer overflows in the (1) fs_get_reply, (2) fs_alloc_glyphs, and (3) fs_read_extent_info functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs reply, which triggers a buffer overflow.
osv
CVE-2014-0210HIGHCVSS 7.5≥ 0, < 1:1.4.7-22014-05-15
CVE-2014-0210 [HIGH] CVE-2014-0210: Multiple buffer overflows in X
Multiple buffer overflows in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs protocol reply to the (1) _fs_recv_conn_setup, (2) fs_read_open_font, (3) fs_read_query_info, (4) fs_read_extent_info, (5) fs_read_glyphs, (6) fs_read_list, or (7) fs_read_list_info function.
osv
CVE-2014-0209MEDIUMCVSS 4.6≥ 0, < 1:1.4.7-22014-05-15
CVE-2014-0209 [MEDIUM] CVE-2014-0209: Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X
Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a directory with a large fonts.dir or fonts.alias file to the font path, which triggers a heap-based buffer overflow, related to metadata.
osv
CVE-2013-6462CRITICALCVSS 9.3≥ 0, < 1:1.4.7-12014-01-09
CVE-2013-6462 [CRITICAL] CVE-2013-6462: Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread
Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.
osv
CVE-2011-2895HIGHCVSS 7.5≥ 0, < 1:1.4.4-12011-08-19
CVE-2011-2895 [HIGH] CVE-2011-2895: The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress
The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table
osv
CVE-2008-0006HIGHCVSS 7.5≥ 0, < 1:1.3.1-22008-01-18
CVE-2008-0006 [HIGH] CVE-2008-0006: Buffer overflow in (1) X
Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table.
osv
CVE-2007-1351HIGHCVSS 8.5v1.2.22007-04-06
CVE-2007-1351 [HIGH] CWE-189 CVE-2007-1351: Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 2007040
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.
nvdosv
CVE-2007-1352LOWCVSS 3.8v1.2.22007-04-06
CVE-2007-1352 [LOW] CVE-2007-1352: Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote a
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.
nvdosv
CVE-2006-3740HIGHCVSS 7.2≥ 0, < 1:1.2.2-12006-09-13
CVE-2006-3740 [HIGH] CVE-2006-3740: Integer overflow in the scan_cidfont function in X
Integer overflow in the scan_cidfont function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted (1) CMap and (2) CIDFont font data with modified item counts in the (a) begincodespacerange, (b) cidrange, and (c) notdefrange sections.
osv
CVE-2006-3739HIGHCVSS 7.2≥ 0, < 1:1.2.2-12006-09-13
CVE-2006-3739 [HIGH] CVE-2006-3739: Integer overflow in the CIDAFM function in X
Integer overflow in the CIDAFM function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted Adobe Font Metrics (AFM) files with a modified number of character metrics (StartCharMetrics), which leads to a heap-based buffer overflow.
osv
CVE-2006-3467HIGHCVSS 7.5≥ 0, < 1:1.2.0-22006-07-21
CVE-2006-3467 [HIGH] CVE-2006-3467: Integer overflow in FreeType before 2
Integer overflow in FreeType before 2.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PCF file, as demonstrated by the Red Hat bad1.pcf test file, due to a partial fix of CVE-2006-1861.
osv