Xi Graphics develops specialized graphics and visualization software, including the Dextop and Accelerated X Server products, which address display acceleration and rendering in Unix and Linux environments. Vulnerabilities associated with the vendor center on memory-buffer handling and related low-level rendering operations, reflecting the boundary-sensitive nature of graphics pipeline code. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xi Graphics over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0679HIGH Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREA | Sep 5, 2002 | 10.0 | 42 | NO | NO |
CVE-2004-0368HIGH Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet. | May 4, 2004 | 10.0 | 29 | NO | NO |
CVE-1999-0778HIGH Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query parameter. | Jun 25, 1999 | 7.2 | 29 | NO | YES |
CVE-2002-0678HIGH CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure | Jul 23, 2002 | 7.2 | 27 | NO | NO |
CVE-2002-0677HIGH CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument | Jul 23, 2002 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xi Graphics.
Media articles that mention a CVE ID that affects a product developed by Xi Graphics — matched by CVE ID, not by vendor name.