← Vulnerability feed

Vulnerability record · CVE-2008-0006 · published 18 January 2008

CVE-2008-0006: Sun solaris libfont memory buffer overflow vulnerability

Sun · Solaris Libfont

Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table.

7.5 CVSS 2.0 High EPSS 5.1% · top 7.9% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
5.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
134References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.gentoo.org/show_bug.cgi?id=204362
http://docs.info.apple.com/article.html?artnum=307562
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01543321
http://jvn.jp/en/jp/JVN88935101/index.html
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001043.html
http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
http://lists.freedesktop.org/archives/xorg/2008-January/031918.html Patch
http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html
http://secunia.com/advisories/28273 Vendor Advisory
http://secunia.com/advisories/28500 Vendor Advisory
http://secunia.com/advisories/28532 Vendor Advisory
http://secunia.com/advisories/28535 Vendor Advisory
http://secunia.com/advisories/28536 Vendor Advisory
http://secunia.com/advisories/28540 Vendor Advisory
http://secunia.com/advisories/28542 Vendor Advisory
http://secunia.com/advisories/28544 Vendor Advisory
http://secunia.com/advisories/28550 Vendor Advisory
http://secunia.com/advisories/28571 Vendor Advisory
http://secunia.com/advisories/28592 Vendor Advisory
http://secunia.com/advisories/28621 Vendor Advisory
http://secunia.com/advisories/28718
http://secunia.com/advisories/28843
http://secunia.com/advisories/28885
http://secunia.com/advisories/28941
http://secunia.com/advisories/29139
http://secunia.com/advisories/29420
http://secunia.com/advisories/29622
http://secunia.com/advisories/29707
http://secunia.com/advisories/30161
http://secunia.com/advisories/32545
http://security.gentoo.org/glsa/glsa-200801-09.xml
http://security.gentoo.org/glsa/glsa-200804-05.xml
http://securitytracker.com/id?1019232
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103192-1 Patch
http://sunsolve.sun.com/search/document.do?assetkey=1-26-201230-1
http://support.avaya.com/elmodocs2/security/ASA-2008-038.htm
http://support.avaya.com/elmodocs2/security/ASA-2008-077.htm
http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml
http://www.kb.cert.org/vuls/id/203220 US Government Resource

Track CVE-2008-0006 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2007-5760X.org xserver vulnerabilityArray index error in the XFree86-Misc extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via a Pass…EPSS 3.3%9.3CVE-2007-6429X.org evi race condition vulnerabilityMultiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request …EPSS 2.5%5.5CVE-2007-2437X.org x window system vulnerabilityThe X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to cau…EPSS 4.4%5.0CVE-2007-5958X.org xserver information exposure vulnerabilityX.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X progra…EPSS 5.3%5.0CVE-2007-6428X.org tog-cup vulnerabilityThe ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the con…EPSS 1.7%9.5CVE-2026-88772Citrix netscaler application delivery controller memory buffer overflow vulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEV8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed

Source: NIST National Vulnerability Database (record CVE-2008-0006), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.