MidnightBSD

Advisories for xfree86

CVE-2011-2504 MEDIUM

Untrusted search path vulnerability in x11perfcomp in XFree86 x11perf before 1.5.4 allows local users to gain privileges via unspecified Trojan horse code in the current working directory.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
xfree86 x11perf 1.5.2
xfree86 x11perf *
xfree86 x11perf 1.5.1
xfree86 x11perf 1.5
CVE-2012-1699 LOW

The ProcSetEventMask function in difs/events.c in the xfs font server for X.Org X11R6 through X11R6.6 and XFree86 before 3.3.3 calls the SendErrToClient function with a mask value instead of a pointer, which allows local users to cause a denial of service (memory corruption and crash) or obtain potentially sensitive information from memory via a SetEventMask request that triggers an invalid pointer dereference.

CVSS 2.0

Severity: LOW

Problem Type: CWE-119,

Products Affected

Vendor Product Version
x x.org_x11 6.1
xfree86 xfree86 *
x x.org_x11 6.4
x x.org_x11 6.6
x x.org_x11 6.3
x x.org_x11 6.0
x x.org_x11 6.5.1