← Vulnerability feed

Vulnerability record · CVE-2002-1510 · published 3 March 2003

CVE-2002-1510: Xfree86 project x11r6 vulnerability

Xfree86 Project · X11r6

xdm, with the authComplain variable set to false, allows arbitrary attackers to connect to the X server if the xdm auth directory does not exist.

10.0 CVSS 2.0 High EPSS 2.0% · top 20.4%
10.0CVSS 2.0 base score
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

xdm, with the authComplain variable set to false, allows arbitrary attackers to connect to the X server if the xdm auth directory does not exist.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1510 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0914Lesstif vulnerabilityMultiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-b…EPSS 8.7%10.0CVE-2004-0083Xfree86 project x11r6 vulnerabilityBuffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via …EPSS 21%10.0CVE-2004-0084Xfree86 project x11r6 vulnerabilityBuffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authent…EPSS 25%10.0CVE-1999-0241Xfree86 project x11r6 vulnerabilityGuessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.EPSS 4.3%8.5CVE-2007-1351Ubuntu linux vulnerabilityInteger overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remot…EPSS 5.6%7.5CVE-2005-0605Lesstif vulnerabilityscan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.EPSS 4.5%7.5CVE-2004-0687X.org x11r6 vulnerabilityMultiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm …EPSS 8.1%7.5CVE-2004-0688X.org x11r6 vulnerabilityMultiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) …EPSS 7.2%

Source: NIST National Vulnerability Database (record CVE-2002-1510), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.