Back

CVE-2004-0084

Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.

Published: Mar 3, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (9)

Vendor Product Version
xfree86_project x11r6 4.1.0
xfree86_project x11r6 4.1.11
xfree86_project x11r6 4.1.12
xfree86_project x11r6 4.2.0
xfree86_project x11r6 4.2.1
xfree86_project x11r6 4.2.1
xfree86_project x11r6 4.3.0
openbsd openbsd 3.3
openbsd openbsd 3.4

GitHub Security Advisory GHSA-4642-rff9-864v

Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 24.86%

Top 2% most likely to be exploited

Threat Score 47.5 / 100

Data Sources

NVD EPSS GitHub