← Vulnerability feed

Vulnerability record · CVE-2013-6462 · published 9 January 2014

CVE-2013-6462: Libxfont memory buffer overflow vulnerability

XX · Libxfont

Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.

9.3 CVSS 2.0 High EPSS 10% · top 4.5% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
10%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
32References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://cgit.freedesktop.org/xorg/lib/libXfont/commit/?id=4d024ac10f964f6bd372ae0dd14f02772a6e5f63 ExploitPatch
http://lists.opensuse.org/opensuse-updates/2014-01/msg00050.html
http://lists.opensuse.org/opensuse-updates/2014-01/msg00052.html
http://lists.x.org/archives/xorg-announce/2014-January/002389.html Vendor Advisory
http://osvdb.org/101842
http://rhn.redhat.com/errata/RHSA-2014-0018.html
http://seclists.org/oss-sec/2014/q1/33
http://secunia.com/advisories/56240 Vendor Advisory
http://secunia.com/advisories/56336
http://secunia.com/advisories/56357
http://secunia.com/advisories/56371
http://www.debian.org/security/2014/dsa-2838
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html
http://www.securityfocus.com/bid/64694
http://www.ubuntu.com/usn/USN-2078-1
https://exchange.xforce.ibmcloud.com/vulnerabilities/90123
http://cgit.freedesktop.org/xorg/lib/libXfont/commit/?id=4d024ac10f964f6bd372ae0dd14f02772a6e5f63 ExploitPatch
http://lists.opensuse.org/opensuse-updates/2014-01/msg00050.html
http://lists.opensuse.org/opensuse-updates/2014-01/msg00052.html
http://lists.x.org/archives/xorg-announce/2014-January/002389.html Vendor Advisory
http://osvdb.org/101842
http://rhn.redhat.com/errata/RHSA-2014-0018.html
http://seclists.org/oss-sec/2014/q1/33
http://secunia.com/advisories/56240 Vendor Advisory
http://secunia.com/advisories/56336
http://secunia.com/advisories/56357
http://secunia.com/advisories/56371
http://www.debian.org/security/2014/dsa-2838
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html
http://www.securityfocus.com/bid/64694
http://www.ubuntu.com/usn/USN-2078-1
https://exchange.xforce.ibmcloud.com/vulnerabilities/90123

Track CVE-2013-6462 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2007-5199Libxfont memory buffer overflow vulnerabilityA single byte overflow in catalogue.c in X.Org libXfont 1.3.1 allows remote attackers to have unspecified impact.EPSS 2.2%9.3CVE-2011-2895Freetype memory buffer overflow vulnerabilityThe LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3…EPSS 8.4%8.8CVE-2026-56002Libxfont heap-based buffer overflow vulnerabilityA heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to exec…EPSS 0.56%8.8CVE-2026-56003Libxfont heap-based buffer overflow vulnerabilityA heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXf…EPSS 0.62%8.8CVE-2026-56001Libxfont heap-based buffer overflow vulnerabilityA heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the…EPSS 0.62%8.5CVE-2015-1804Libxfont vulnerabilityThe bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly perform type conversion fo…EPSS 5.0%8.5CVE-2015-1803Canonical ubuntu linux vulnerabilityThe bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps i…EPSS 4.9%8.5CVE-2015-1802Libxfont memory buffer overflow vulnerabilityThe bdfReadProperties function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 allows remote authenticated users to cause a…EPSS 4.9%

Source: NIST National Vulnerability Database (record CVE-2013-6462), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.