Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Xdm
(X\.org)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 2 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2006-10-10 | CVE-2006-5215 | The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file. | Netbsd, Solaris, Sunos, Xdm | N/A | ||
2006-08-29 | CVE-2006-4447 | X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit. | Emu\-Linux\-X87\-Xlibs, X11r6, X11r7, Xdm, Xf86dga, Xinit, Xload, Xorg\-Server, Xterm | N/A |