// For flags

CVE-2004-0914

openmotif21 stack overflows in libxpm

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file. NOTE: it is highly likely that this candidate will be SPLIT into other candidates in the future, per CVE's content decisions.

Múltiples vulnerabilidades en libXpm 6.8.1 y anteriores, usada en XFree86 y otros paquetes, incluyendo
(1) múltiples desbordamientos de enteros,
(2) accesos de memoria fuera de límites,
(3) atravesamiento de directorios,
(4) metacaractéres de shell,
(5) bucles infinitos, y
(6) filtraciones de memoria
podrían permitir a atacantes remotos obtener información sensible, causar una denegación de servicio (caída de aplicación) o ejecutar código de su elección mediante un cierto fichero de imagen XPM.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2004-09-27 CVE Reserved
  • 2004-12-12 CVE Published
  • 2023-11-22 EPSS Updated
  • 2024-08-08 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (24)
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Lesstif
Search vendor "Lesstif"
Lesstif
Search vendor "Lesstif" for product "Lesstif"
0.93
Search vendor "Lesstif" for product "Lesstif" and version "0.93"
-
Affected
Lesstif
Search vendor "Lesstif"
Lesstif
Search vendor "Lesstif" for product "Lesstif"
0.93.12
Search vendor "Lesstif" for product "Lesstif" and version "0.93.12"
-
Affected
Lesstif
Search vendor "Lesstif"
Lesstif
Search vendor "Lesstif" for product "Lesstif"
0.93.18
Search vendor "Lesstif" for product "Lesstif" and version "0.93.18"
-
Affected
Lesstif
Search vendor "Lesstif"
Lesstif
Search vendor "Lesstif" for product "Lesstif"
0.93.34
Search vendor "Lesstif" for product "Lesstif" and version "0.93.34"
-
Affected
Lesstif
Search vendor "Lesstif"
Lesstif
Search vendor "Lesstif" for product "Lesstif"
0.93.36
Search vendor "Lesstif" for product "Lesstif" and version "0.93.36"
-
Affected
Lesstif
Search vendor "Lesstif"
Lesstif
Search vendor "Lesstif" for product "Lesstif"
0.93.40
Search vendor "Lesstif" for product "Lesstif" and version "0.93.40"
-
Affected
Lesstif
Search vendor "Lesstif"
Lesstif
Search vendor "Lesstif" for product "Lesstif"
0.93.91
Search vendor "Lesstif" for product "Lesstif" and version "0.93.91"
-
Affected
Lesstif
Search vendor "Lesstif"
Lesstif
Search vendor "Lesstif" for product "Lesstif"
0.93.94
Search vendor "Lesstif" for product "Lesstif" and version "0.93.94"
-
Affected
Lesstif
Search vendor "Lesstif"
Lesstif
Search vendor "Lesstif" for product "Lesstif"
0.93.96
Search vendor "Lesstif" for product "Lesstif" and version "0.93.96"
-
Affected
X.org
Search vendor "X.org"
X11r6
Search vendor "X.org" for product "X11r6"
6.7.0
Search vendor "X.org" for product "X11r6" and version "6.7.0"
-
Affected
X.org
Search vendor "X.org"
X11r6
Search vendor "X.org" for product "X11r6"
6.8
Search vendor "X.org" for product "X11r6" and version "6.8"
-
Affected
X.org
Search vendor "X.org"
X11r6
Search vendor "X.org" for product "X11r6"
6.8.1
Search vendor "X.org" for product "X11r6" and version "6.8.1"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
3.3
Search vendor "Xfree86 Project" for product "X11r6" and version "3.3"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
3.3.2
Search vendor "Xfree86 Project" for product "X11r6" and version "3.3.2"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
3.3.3
Search vendor "Xfree86 Project" for product "X11r6" and version "3.3.3"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
3.3.4
Search vendor "Xfree86 Project" for product "X11r6" and version "3.3.4"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
3.3.5
Search vendor "Xfree86 Project" for product "X11r6" and version "3.3.5"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
3.3.6
Search vendor "Xfree86 Project" for product "X11r6" and version "3.3.6"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
4.0
Search vendor "Xfree86 Project" for product "X11r6" and version "4.0"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
4.0.1
Search vendor "Xfree86 Project" for product "X11r6" and version "4.0.1"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
4.0.2.11
Search vendor "Xfree86 Project" for product "X11r6" and version "4.0.2.11"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
4.0.3
Search vendor "Xfree86 Project" for product "X11r6" and version "4.0.3"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
4.1.0
Search vendor "Xfree86 Project" for product "X11r6" and version "4.1.0"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
4.1.11
Search vendor "Xfree86 Project" for product "X11r6" and version "4.1.11"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
4.1.12
Search vendor "Xfree86 Project" for product "X11r6" and version "4.1.12"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
4.2.0
Search vendor "Xfree86 Project" for product "X11r6" and version "4.2.0"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
4.2.1
Search vendor "Xfree86 Project" for product "X11r6" and version "4.2.1"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
4.2.1
Search vendor "Xfree86 Project" for product "X11r6" and version "4.2.1"
errata
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
4.3.0
Search vendor "Xfree86 Project" for product "X11r6" and version "4.3.0"
-
Affected
Gentoo
Search vendor "Gentoo"
Linux
Search vendor "Gentoo" for product "Linux"
*-
Affected
Redhat
Search vendor "Redhat"
Fedora Core
Search vendor "Redhat" for product "Fedora Core"
core_2.0
Search vendor "Redhat" for product "Fedora Core" and version "core_2.0"
-
Affected
Redhat
Search vendor "Redhat"
Fedora Core
Search vendor "Redhat" for product "Fedora Core"
core_3.0
Search vendor "Redhat" for product "Fedora Core" and version "core_3.0"
-
Affected
Suse
Search vendor "Suse"
Suse Linux
Search vendor "Suse" for product "Suse Linux"
1.0
Search vendor "Suse" for product "Suse Linux" and version "1.0"
desktop
Affected
Suse
Search vendor "Suse"
Suse Linux
Search vendor "Suse" for product "Suse Linux"
8
Search vendor "Suse" for product "Suse Linux" and version "8"
enterprise_server
Affected
Suse
Search vendor "Suse"
Suse Linux
Search vendor "Suse" for product "Suse Linux"
8.1
Search vendor "Suse" for product "Suse Linux" and version "8.1"
-
Affected
Suse
Search vendor "Suse"
Suse Linux
Search vendor "Suse" for product "Suse Linux"
8.2
Search vendor "Suse" for product "Suse Linux" and version "8.2"
-
Affected
Suse
Search vendor "Suse"
Suse Linux
Search vendor "Suse" for product "Suse Linux"
9.0
Search vendor "Suse" for product "Suse Linux" and version "9.0"
-
Affected
Suse
Search vendor "Suse"
Suse Linux
Search vendor "Suse" for product "Suse Linux"
9.0
Search vendor "Suse" for product "Suse Linux" and version "9.0"
enterprise_server
Affected
Suse
Search vendor "Suse"
Suse Linux
Search vendor "Suse" for product "Suse Linux"
9.1
Search vendor "Suse" for product "Suse Linux" and version "9.1"
-
Affected
Suse
Search vendor "Suse"
Suse Linux
Search vendor "Suse" for product "Suse Linux"
9.2
Search vendor "Suse" for product "Suse Linux" and version "9.2"
-
Affected