← Back

CVE-2004-0688

nvd nist
Published: Oct 20, 2004Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.

Affected (23)

Products: X.org: X11r6 · Xfree86 Project: X11r6 · Openbsd: Openbsd · +1 more
Show all products
1 product
X11r6
X11r6
1 product
Openbsd
1 product
Suse Linux
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
X.org
Version 6.7.0
Version 6.8
Xfree86 Project
Version 3.3.6
Version 4.0.1
Version 4.0.2.11
Version 4.0.3
Version 4.0
Version 4.1.0
Version 4.1.11
Version 4.1.12
Version 4.2.0
Version 4.2.1
Version 4.2.1
Version 4.3.0
Configuration B
9 vulnerable
Vulnerable SoftwareAffected Versions
Openbsd
Version 3.4
Version 3.5
Suse
Version 8.1
Version 8.2
Version 8
Version 9.0
Version 9.0
Version 9.0
Version 9.1

References (46)

Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.