Back

CVE-2004-0368

Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.

Published: May 4, 2004 Modified: Jun 16, 2026
CWE-119

CVSS Metrics

Affected Products (12)

Vendor Product Version
open_group cde_common_desktop_environment 1.0.1
open_group cde_common_desktop_environment 1.0.2
open_group cde_common_desktop_environment 1.1
open_group cde_common_desktop_environment 1.2
open_group cde_common_desktop_environment 2.0
open_group cde_common_desktop_environment 2.1
open_group cde_common_desktop_environment 2.1.20
xi_graphics dextop 2.1
xi_graphics dextop 3.0
ibm aix 4.3.3
ibm aix 5.1
ibm aix 5.2

GitHub Security Advisory GHSA-x2m8-j98q-33px

Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 10.58%

Top 5% most likely to be exploited

Threat Score 43.2 / 100

Data Sources

NVD EPSS GitHub