peter bassill · operator
$ cve CVE-2001-1086 JSON

CVE-2001-1086 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.8% (pctl 86)

Patch early

A public exploit exists.

Description

XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.84% — more likely to be exploited than 86% of all CVEs
On CISA KEVno
Public exploityes
Published2001-07-04
Last modified2026-06-16

Affected (1)

VendorProduct
xfree86 projectx11r6

Public exploits

SourceTitleDate
exploit-dbXFree86 X11R6 3.3 XDM - Session Cookie Guessing2001-06-24

References

→ the Explorer  ·  watch your stack  ·  NVD