← Back

Xli

xli

4 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Xli
xli

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Xli
Xloadimage
2Xli
Xloadimage
Apr 16, 2026
Oct 7, 2005
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in xloadimage 4.1 and earlier, and xli, might allow user-assisted attackers to execute arbitrary code via a long title name in a NIFF file, which triggers the overflow during (1) zoom, (2) reduce, or (3)...Show more
Buffer overflow in xloadimage 4.1 and earlier, and xli, might allow user-assisted attackers to execute arbitrary code via a long title name in a NIFF file, which triggers the overflow during (1) zoom, (2) reduce, or (3) rotate operations.Show less
3Altlinux
SuseXli
3Alt Linux
Suse LinuxXli
Apr 16, 2026
Mar 2, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be related to integer overflows in PPM file...Show more
Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be related to integer overflows in PPM files.Show less
3Altlinux
SuseXli
3Alt Linux
Suse LinuxXli
Apr 16, 2026
Mar 2, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.
2Xli
Xloadimage
2Xli
Xloadimage
Apr 16, 2026
Oct 18, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via a FACES format image containing a long (1) Firstname or (2) Lastname field.