peter bassill · operator
$ cve CVE-2004-0084 JSON

CVE-2004-0084 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 24.9% (pctl 98)

Patch early

A public exploit exists.

Description

Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS24.86% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2004-03-03
Last modified2026-06-16

Affected (2)

VendorProduct
openbsdopenbsd
xfree86 projectx11r6

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD