David Bagley maintains a narrow portfolio centered on xlock and xlockmore, X Window System screen-locking utilities that have been in long-term circulation on Unix and Linux systems. The observed vulnerabilities reflect the complexity of credential handling and display-server interaction inherent to these lock-screen implementations, with recorded weakness classes primarily classified under broader categories pending more specific technical detail. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by David Bagley over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2000-0763HIGH xlockmore and xlockf do not properly cleanse user-injected format strings, which allows local users to gain root privileges via the -d option. | Oct 20, 2000 | 7.2 | 27 | NO | YES |
The (1) checkPasswd and (2) checkGroupXlockPasswds functions in xlockmore before 5.43 do not properly handle when a NULL value is returned upon an error by the crypt or dispcrypt f | May 30, 2014 | 2.1 | 11 | NO | NO |
Buffer overflow in xlockmore xlock program version 4.16 and earlier allows local users to read sensitive data from memory via a long -mode option. | May 29, 2000 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by David Bagley.
Media articles that mention a CVE ID that affects a product developed by David Bagley — matched by CVE ID, not by vendor name.