Xli is a niche image-display utility with a minimal vulnerability footprint, centered on its single-product line. The observed disclosures involve memory-buffer handling issues and categorization gaps in vulnerability classification; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xli over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0775HIGH Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via a FACES format image containing a long (1) Firstname or (2) | Oct 18, 2001 | 7.5 | 38 | NO | YES |
CVE-2005-0638HIGH xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly qu | Mar 2, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-0639HIGH Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be | Mar 2, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-3178MEDIUM Buffer overflow in xloadimage 4.1 and earlier, and xli, might allow user-assisted attackers to execute arbitrary code via a long title name in a NIFF file, which triggers the overf | Oct 7, 2005 | 5.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xli.
Media articles that mention a CVE ID that affects a product developed by Xli — matched by CVE ID, not by vendor name.