Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-56002

Опубликовано: 08 июл. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.5

Описание

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

РелизСтатусПримечание
devel

not-affected

2.0.8-1
esm-infra-legacy/trusty

released

1:1.4.7-1ubuntu0.4+esm2
esm-infra-legacy/xenial

released

1:1.5.1-1ubuntu0.16.04.4+esm2
esm-infra/bionic

released

1:2.0.3-1ubuntu0.1~esm2
esm-infra/focal

released

1:2.0.3-1ubuntu0.20.04.1~esm2
jammy

released

1:2.0.5-1ubuntu0.2
noble

released

1:2.0.6-1+deb13u1build0.24.04.2
questing

ignored

end of life, was needs-triage
resolute

released

1:2.0.6-2ubuntu0.2
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/xenial

needs-triage

jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 35%
0.00428
Низкий

8.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
redhat
24 дня назад

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

CVSS3: 8.5
nvd
23 дня назад

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

CVSS3: 8.5
msrc
23 дня назад

libXfont2 PCF Font Parsing Heap Buffer Overflow

CVSS3: 8.5
debian
23 дня назад

A heap bufferflow in pcfReadFont() due to missing glyph bounds checkin ...

CVSS3: 8.5
github
23 дня назад

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

EPSS

Процентиль: 35%
0.00428
Низкий

8.5 High

CVSS3