MidnightBSD

Advisories for xi_graphics

CVE-1999-0778 HIGH

Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query parameter.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
xi_graphics accelerated-x_server 4
xi_graphics accelerated-x_server 5
CVE-2002-0677 HIGH

CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sun sunos 5.8
sgi irix 6.5.13
xi_graphics dextop 2.1
sgi irix 6.5.8
sun sunos 5.7
sgi irix 6.5.6
sgi irix 6.0
sgi irix 6.5.5
compaq tru64 4.0f
hp hp-ux 10.10
hp hp-ux 11.00
sun solaris 2.6
compaq tru64 4.0g
sgi irix 6.3
sgi irix 6.5.12
caldera unixware 7.1_.0
sgi irix 5.3
hp hp-ux 10.24
sgi irix 6.5.2
sgi irix 6.4
sun sunos 5.5.1
hp hp-ux 11.11
caldera unixware 7.1.1
sgi irix 6.1
compaq tru64 5.1
compaq tru64 5.0a
hp hp-ux 10.20
sgi irix 6.5
sgi irix 6.0.1
sgi irix 6.5.3
compaq tru64 5.1a
sgi irix 5.2
sgi irix 6.5.7
sgi irix 6.5.15
sgi irix 6.2
sgi irix 6.5.4
sgi irix 6.5.11
sgi irix 6.5.10
sgi irix 6.5.14
caldera openunix 8.0
ibm aix 4.3.3
caldera unixware 7
sgi irix 6.5.16
sgi irix 6.5.9
ibm aix 5.1
sgi irix 6.5.1
CVE-2002-0678 HIGH

CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sun sunos 5.8
sgi irix 6.5.13
xi_graphics dextop 2.1
sgi irix 6.5.8
sun sunos 5.7
sgi irix 6.5.6
sgi irix 6.0
sgi irix 6.5.5
compaq tru64 4.0f
hp hp-ux 10.10
hp hp-ux 11.00
sun solaris 2.6
compaq tru64 4.0g
sgi irix 6.3
sgi irix 6.5.12
sgi irix 5.3
hp hp-ux 10.24
sgi irix 6.5.2
sun solaris 9.0
sgi irix 6.4
sun sunos 5.5.1
hp hp-ux 11.11
caldera unixware 7.1.1
sgi irix 6.1
compaq tru64 5.1
compaq tru64 5.0a
hp hp-ux 10.20
sgi irix 6.5
sgi irix 6.0.1
sgi irix 6.5.3
compaq tru64 5.1a
sgi irix 5.2
sgi irix 6.5.7
sgi irix 6.5.15
sgi irix 6.2
sgi irix 6.5.4
caldera unixware 7.1.0
sgi irix 6.5.11
sgi irix 6.5.10
caldera unixware 7.0
sgi irix 6.5.14
caldera openunix 8.0
ibm aix 4.3.3
sgi irix 6.5.16
sgi irix 6.5.9
ibm aix 5.1
sgi irix 6.5.1
CVE-2002-0679 HIGH

Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sun sunos 5.8
compaq tru64 5.1
compaq tru64 5.0a
xi_graphics dextop 2.1
hp hp-ux 10.20
sun sunos 5.7
compaq tru64 5.1a
compaq tru64 4.0f
hp hp-ux 10.10
hp hp-ux 11.00
sun solaris 2.6
compaq tru64 4.0g
caldera unixware 7.1.0
caldera unixware 7.0
hp hp-ux 10.24
caldera openunix 8.0
sun solaris 9.0
ibm aix 4.3.3
sun sunos 5.5.1
ibm aix 5.1
hp hp-ux 11.11
caldera unixware 7.1.1
CVE-2004-0368 HIGH

Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
open_group cde_common_desktop_environment 1.0.1
open_group cde_common_desktop_environment 2.0
xi_graphics dextop 2.1
open_group cde_common_desktop_environment 2.1
xi_graphics dextop 3.0
open_group cde_common_desktop_environment 2.1.20
open_group cde_common_desktop_environment 1.0.2
ibm aix 5.2
ibm aix 4.3.3
ibm aix 5.1
open_group cde_common_desktop_environment 1.1
open_group cde_common_desktop_environment 1.2