← Vulnerability feed

Vulnerability record · CVE-2005-2495 · published 15 September 2005

CVE-2005-2495: Xfree86 project xfree86 vulnerability

Xfree86 Project · Xfree86

Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.

5.1 CVSS 2.0 Medium EPSS 3.9% · top 10.0% CWE-189 · CWE-189
5.1CVSS 2.0 base score
3.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
76References
16 Jun 2026Last modified by NVD

Description

Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.

AV:N/AC:H/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.22/SCOSA-2006.22.txt
ftp://patches.sgi.com/support/free/security/advisories/20060403-01-U
http://marc.info/?l=bugtraq&m=112690609622266&w=2
http://secunia.com/advisories/16777 Vendor Advisory
http://secunia.com/advisories/16790 Vendor Advisory
http://secunia.com/advisories/17044 Vendor Advisory
http://secunia.com/advisories/17215 Vendor Advisory
http://secunia.com/advisories/17258 Vendor Advisory
http://secunia.com/advisories/17278 Vendor Advisory
http://secunia.com/advisories/19624 Vendor Advisory
http://secunia.com/advisories/19796 Vendor Advisory
http://secunia.com/advisories/21318 Vendor Advisory
http://securitytracker.com/id?1014887
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101926-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101953-1
http://support.avaya.com/elmodocs2/security/ASA-2005-218.pdf
http://support.avaya.com/elmodocs2/security/ASA-2005-226.pdf
http://www.debian.org/security/2005/dsa-816
http://www.gentoo.org/security/en/glsa/glsa-200509-07.xml
http://www.kb.cert.org/vuls/id/102441 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2005:164
http://www.novell.com/linux/security/advisories/2005_23_sr.html
http://www.novell.com/linux/security/advisories/2005_56_xserver.html
http://www.osvdb.org/19352
http://www.redhat.com/support/errata/RHSA-2005-329.html
http://www.redhat.com/support/errata/RHSA-2005-396.html Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2005-501.html Vendor Advisory
http://www.securityfocus.com/advisories/9285
http://www.securityfocus.com/advisories/9286
http://www.securityfocus.com/archive/1/427045/100/0/threaded
http://www.securityfocus.com/archive/1/442163/100/0/threaded
http://www.securityfocus.com/bid/14807
http://www.vupen.com/english/advisories/2006/3140 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/22244
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1044
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9615
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A998
https://www.ubuntu.com/usn/usn-182-1/
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.22/SCOSA-2006.22.txt
ftp://patches.sgi.com/support/free/security/advisories/20060403-01-U

Track CVE-2005-2495 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2005-2495), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.