Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-0006

24
FAUCET Score

CVE-2008-0006 describes a buffer overflow vulnerability in X.Org Xserver versions prior to 1.4.1 and the libfont/libXfont libraries on platforms like Sun Solaris. This flaw allows unauthenticated, remote attackers to execute arbitrary code by supplying a specially crafted PCF font file with an oversized difference in the PCF_BDF_ENCODINGS table. With a CVSS score of 7.5, this vulnerability is considered highly severe due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the high FAUCET Risk Score of 93/100 indicates its significant potential impact if exploited.

Impacted Technologies

VendorProductVersion(s)CPE
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:a:sun:solaris_libfont:*:*:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:a:sun:solaris_libxfont:*:*:*:*:*:*:*:*
<= 1.4CPE matchmatch criteria
cpe:2.3:a:x.org:xserver:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
5.11%
Probability of exploitation in next 30 days
EPSS Percentile
91.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0511 is in the 85th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: XFree86-0:4.1.0-86.EL
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: XFree86-0:4.3.0-126.EL
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: xorg-x11-0:6.8.2-1.EL.33.0.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: libXfont-0:1.2.2-1.0.3.el5_1
View patch

Vendor Advisories (1)

redhatCVE-2008-0006Important

Xorg / XFree86 PCF font parser buffer overflow

Jan 17, 2008

References

bugs.gentoo.org / show_bug.cgi
docs.info.apple.com / article.html
h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
jvndb.jvn.jp / ja/contents/2008/JVNDB-2008-001043.html
jvn.jp / en/jp/JVN88935101/index.html
lists.apple.com / archives/security-announce/2008/Mar/msg00001.html
lists.freedesktop.org / archives/xorg/2008-January/031918.html
Patch
lists.opensuse.org / opensuse-security-announce/2008-01/msg00004.html
lists.opensuse.org / opensuse-security-announce/2008-04/msg00005.html
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/28273
Vendor Advisory
secunia.com / advisories/28500
Vendor Advisory
secunia.com / advisories/28532
Vendor Advisory
secunia.com / advisories/28535
Vendor Advisory
secunia.com / advisories/28536
Vendor Advisory
secunia.com / advisories/28540
Vendor Advisory
secunia.com / advisories/28542
Vendor Advisory
secunia.com / advisories/28544
Vendor Advisory
secunia.com / advisories/28550
Vendor Advisory
secunia.com / advisories/28571
Vendor Advisory
secunia.com / advisories/28592
Vendor Advisory
secunia.com / advisories/28621
Vendor Advisory
secunia.com / advisories/28718
secunia.com / advisories/28843
secunia.com / advisories/28885
secunia.com / advisories/28941
secunia.com / advisories/29139
secunia.com / advisories/29420
secunia.com / advisories/29622
secunia.com / advisories/29707
secunia.com / advisories/30161
secunia.com / advisories/32545
security.gentoo.org / glsa/glsa-200801-09.xml
security.gentoo.org / glsa/glsa-200804-05.xml
securitytracker.com / id
exchange.xforce.ibmcloud.com / vulnerabilities/39767
issues.rpath.com / browse/RPL-2010
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10021
sunsolve.sun.com / search/document.do
Patch
sunsolve.sun.com / search/document.do
support.avaya.com / elmodocs2/security/ASA-2008-038.htm
support.avaya.com / elmodocs2/security/ASA-2008-077.htm
usn.ubuntu.com / 571-1
redhat.com / archives/fedora-package-announce/2008-January/msg00641.html
redhat.com / archives/fedora-package-announce/2008-January/msg00674.html
redhat.com / archives/fedora-package-announce/2008-January/msg00704.html
redhat.com / archives/fedora-package-announce/2008-January/msg00771.html
www14.software.ibm.com / webapp/set2/subscriptions/ijhifoeblist
gentoo.org / security/en/glsa/glsa-200805-07.xml
kb.cert.org / vuls/id/203220
US Government Resource
mandriva.com / security/advisories
mandriva.com / security/advisories
mandriva.com / security/advisories
openbsd.org / errata41.html
openbsd.org / errata42.html
redhat.com / support/errata/RHSA-2008-0029.html
redhat.com / support/errata/RHSA-2008-0030.html
redhat.com / support/errata/RHSA-2008-0064.html
securityfocus.com / archive/1/487335/100/0/threaded
securityfocus.com / bid/27336
Patch
securityfocus.com / bid/27352
vupen.com / english/advisories/2008/0179
vupen.com / english/advisories/2008/0184
vupen.com / english/advisories/2008/0497/references
vupen.com / english/advisories/2008/0703
vupen.com / english/advisories/2008/0924/references
vupen.com / english/advisories/2008/3000