
CVE-2001-1086 – XFree86 X11R6 3.3 XDM - Session Cookie Guessing
https://notcve.org/view.php?id=CVE-2001-1086
04 Jul 2001 — XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack. • https://www.exploit-db.com/exploits/20993 •

CVE-2000-0504 – Gnome 1.0/1.1 / Group X 11.0 / XFree86 X11R6 3.3.x/4.0 - Denial of Service
https://notcve.org/view.php?id=CVE-2000-0504
19 Jun 2000 — libICE in XFree86 allows remote attackers to cause a denial of service by specifying a large value which is not properly checked by the SKIP_STRING macro. • https://www.exploit-db.com/exploits/20023 •

CVE-2000-0620
https://notcve.org/view.php?id=CVE-2000-0620
19 Jun 2000 — libX11 X library allows remote attackers to cause a denial of service via a resource mask of 0, which causes libX11 to go into an infinite loop. • http://marc.info/?l=bugtraq&m=96146116627474&w=2 •

CVE-2000-0476 – Eterm 0.8.10 / rxvt 2.6.1 / PuTTY 0.48 / X11R6 3.3.3/4.0 - Denial of Service
https://notcve.org/view.php?id=CVE-2000-0476
01 Jun 2000 — xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force the window to be resized. • https://www.exploit-db.com/exploits/19984 •

CVE-2000-0453 – XFree86 X11R6 3.3.5/3.3.6/4.0 Xserver - Denial of Service
https://notcve.org/view.php?id=CVE-2000-0453
18 May 2000 — XFree86 3.3.x and 4.0 allows a user to cause a denial of service via a negative counter value in a malformed TCP packet that is sent to port 6000. • https://www.exploit-db.com/exploits/19950 •

CVE-2000-0285
https://notcve.org/view.php?id=CVE-2000-0285
16 Apr 2000 — Buffer overflow in XFree86 3.3.x allows local users to execute arbitrary commands via a long -xkbmap parameter. • http://archives.neohapsis.com/archives/bugtraq/2000-04/0076.html •

CVE-1999-0433 – X11R6 3.3.3 - Symlink
https://notcve.org/view.php?id=CVE-1999-0433
21 Mar 1999 — XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service. • https://www.exploit-db.com/exploits/19257 •

CVE-1999-0241
https://notcve.org/view.php?id=CVE-1999-0241
01 Nov 1995 — Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0241 •