Search CVE reports


Toggle filters

1 – 10 of 23 results

Status is adjusted based on your filters.


CVE-2026-59679

Medium priority
Needs evaluation

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents...

2 affected packages

libxfont, libxfont2

Package 16.04 LTS
libxfont Not affected
libxfont2 Needs evaluation
Show less packages

CVE-2026-44950

Medium priority
Needs evaluation

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer....

2 affected packages

libxfont, libxfont2

Package 16.04 LTS
libxfont Not affected
libxfont2 Needs evaluation
Show less packages

CVE-2026-56003

Medium priority

Some fixes available 1 of 2

A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to...

2 affected packages

libxfont, libxfont2

Package 16.04 LTS
libxfont Fixed
libxfont2 Needs evaluation
Show less packages

CVE-2026-56002

Medium priority

Some fixes available 1 of 2

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

2 affected packages

libxfont, libxfont2

Package 16.04 LTS
libxfont Fixed
libxfont2 Needs evaluation
Show less packages

CVE-2026-56001

Medium priority

Some fixes available 1 of 2

A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont

2 affected packages

libxfont, libxfont2

Package 16.04 LTS
libxfont Fixed
libxfont2 Needs evaluation
Show less packages

CVE-2017-16611

Medium priority
Fixed

In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.

3 affected packages

libxfont, libxfont1, libxfont2

Package 16.04 LTS
libxfont Fixed
libxfont1 Not in release
libxfont2 Fixed
Show less packages

CVE-2017-13722

Medium priority
Fixed

In the pcfGetProperties function in bitmap/pcfread.c in libXfont through 1.5.2 and 2.x before 2.0.2, a missing boundary check (for PCF files) could be used by local attackers authenticated to an Xserver for a buffer over-read, for...

3 affected packages

libxfont, libxfont1, libxfont2

Package 16.04 LTS
libxfont Fixed
libxfont1 Not in release
libxfont2 Fixed
Show less packages

CVE-2017-13720

Low priority
Fixed

In the PatternMatch function in fontfile/fontdir.c in libXfont through 1.5.2 and 2.x before 2.0.2, an attacker with access to an X connection can cause a buffer over-read during pattern matching of fonts, leading to information...

3 affected packages

libxfont, libxfont1, libxfont2

Package 16.04 LTS
libxfont Fixed
libxfont1 Not in release
libxfont2 Fixed
Show less packages

CVE-2007-5199

Medium priority
Not affected

A single byte overflow in catalogue.c in X.Org libXfont 1.3.1 allows remote attackers to have unspecified impact.

1 affected package

libxfont

Package 16.04 LTS
libxfont Not affected
Show less packages

CVE-2015-1804

Medium priority

The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly perform type conversion for metrics values, which allows remote authenticated users to cause a denial of...

1 affected package

libxfont

Package 16.04 LTS
libxfont —
Show less packages