Количество 15
Количество 15
openSUSE-SU-2026:21539-1
Security update for libXfont2
SUSE-SU-2026:3500-1
Security update for libXfont2
SUSE-SU-2026:3499-1
Security update for libXfont2
RLSA-2026:55448
Important: libXfont2 security update
RLSA-2026:55447
Important: libXfont2 security update
RLSA-2026:55446
Important: libXfont2 security update
ELSA-2026-55448
ELSA-2026-55448: libXfont2 security update (IMPORTANT)
ELSA-2026-55447
ELSA-2026-55447: libXfont2 security update (IMPORTANT)
ELSA-2026-55446
ELSA-2026-55446: libXfont2 security update (IMPORTANT)
CVE-2026-59679
[Font Server Client encoding Out-Of-Bounds Read/Write]
CVE-2026-59679
A flaw was found in the libXfont2 font-server client. A remote attacker, by operating a malicious font server, could exploit an out-of-bounds read/write vulnerability. This occurs because the client incorrectly handles font data, leading to an out-of-bounds memory access. This can lead to privilege escalation if the X server runs with root privileges, or a denial of service (crash) if it runs as an unprivileged user.
CVE-2026-59679
[Font Server Client encoding Out-Of-Bounds Read/Write]
CVE-2026-44950
[Font Server Client Cumulative Glyph Data Heap Buffer Overflow]
CVE-2026-44950
A flaw was found in the libXfont2 font-server client. This heap buffer overflow vulnerability allows a malicious font server to send specially crafted glyph data. The fs_read_glyphs() function fails to properly validate the total size of the incoming data, leading to an overwrite of memory beyond the intended buffer. If the X server runs as a privileged user, this could result in privilege escalation, allowing an attacker to gain higher access. If the X server runs as an unprivileged user, it could lead to a denial of service, causing the system to crash.
CVE-2026-44950
[Font Server Client Cumulative Glyph Data Heap Buffer Overflow]
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
openSUSE-SU-2026:21539-1 Security update for libXfont2 | 30 дней назад | |||
SUSE-SU-2026:3500-1 Security update for libXfont2 | около 1 месяца назад | |||
SUSE-SU-2026:3499-1 Security update for libXfont2 | около 1 месяца назад | |||
RLSA-2026:55448 Important: libXfont2 security update | 18 дней назад | |||
RLSA-2026:55447 Important: libXfont2 security update | 18 дней назад | |||
RLSA-2026:55446 Important: libXfont2 security update | 18 дней назад | |||
ELSA-2026-55448 ELSA-2026-55448: libXfont2 security update (IMPORTANT) | 19 дней назад | |||
ELSA-2026-55447 ELSA-2026-55447: libXfont2 security update (IMPORTANT) | 19 дней назад | |||
ELSA-2026-55446 ELSA-2026-55446: libXfont2 security update (IMPORTANT) | 19 дней назад | |||
CVE-2026-59679 [Font Server Client encoding Out-Of-Bounds Read/Write] | около 1 месяца назад | |||
CVE-2026-59679 A flaw was found in the libXfont2 font-server client. A remote attacker, by operating a malicious font server, could exploit an out-of-bounds read/write vulnerability. This occurs because the client incorrectly handles font data, leading to an out-of-bounds memory access. This can lead to privilege escalation if the X server runs with root privileges, or a denial of service (crash) if it runs as an unprivileged user. | CVSS3: 7.5 | около 1 месяца назад | ||
CVE-2026-59679 [Font Server Client encoding Out-Of-Bounds Read/Write] | - | |||
CVE-2026-44950 [Font Server Client Cumulative Glyph Data Heap Buffer Overflow] | около 1 месяца назад | |||
CVE-2026-44950 A flaw was found in the libXfont2 font-server client. This heap buffer overflow vulnerability allows a malicious font server to send specially crafted glyph data. The fs_read_glyphs() function fails to properly validate the total size of the incoming data, leading to an overwrite of memory beyond the intended buffer. If the X server runs as a privileged user, this could result in privilege escalation, allowing an attacker to gain higher access. If the X server runs as an unprivileged user, it could lead to a denial of service, causing the system to crash. | CVSS3: 7.5 | около 1 месяца назад | ||
CVE-2026-44950 [Font Server Client Cumulative Glyph Data Heap Buffer Overflow] | - |
Уязвимостей на страницу