CVE-2015-1802
CVE-2015-1802 is a high-severity vulnerability in X Libxfont with a CVSS 2.0 base score of 8.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-119.
Key facts
- Severity: High (CVSS 2.0 base score 8.5)
- EPSS exploit prediction: 5% (91st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-119
- Affected product: X Libxfont
- Published:
- Last modified:
Description
The bdfReadProperties function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 allows remote authenticated users to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a (1) negative or (2) large property count in a BDF font file.
Frequently asked questions
- What is CVE-2015-1802?
- The bdfReadProperties function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 allows remote authenticated users to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a (1) negative or (2) large property count in a BDF font file.
- How severe is CVE-2015-1802?
- CVE-2015-1802 has a CVSS 2.0 base score of 8.5, rated high severity.
- Is CVE-2015-1802 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 5% (91st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2015-1802?
- CVE-2015-1802 primarily affects X Libxfont. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2015-1802?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2015-1802 published?
- CVE-2015-1802 was published on 2015-03-20 and last updated on 2026-06-17.
References
- http://advisories.mageia.org/MGASA-2015-0113.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152497.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152838.html
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00032.html
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00005.html
- http://rhn.redhat.com/errata/RHSA-2015-1708.html
- http://www.debian.org/security/2015/dsa-3194
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:145
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- http://www.securityfocus.com/bid/73277
- http://www.securitytracker.com/id/1031935
- http://www.ubuntu.com/usn/USN-2536-1
- http://www.x.org/wiki/Development/Security/Advisory-2015-03-17/
- https://security.gentoo.org/glsa/201507-21
Affected products (2)
- cpe:2.3:a:x:libxfont:*:*:*:*:*:*:*:*
- cpe:2.3:a:x:libxfont:1.5.0:*:*:*:*:*:*:*
More vulnerabilities in X Libxfont
- CVE-2007-5199 — Critical (CVSS 9.8): A single byte overflow in catalogue.c in X.Org libXfont 1.3.1 allows remote attackers to have unspecified impact.
- CVE-2013-6462 — Critical (CVSS 9.3): Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6…
- CVE-2011-2895 — Critical (CVSS 9.3): The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and…
- CVE-2026-56003 — High (CVSS 8.5): A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2…
- CVE-2026-56002 — High (CVSS 8.5): A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers…
- CVE-2026-56001 — High (CVSS 8.5): A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used…
All CVEs affecting X Libxfont →
Other CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) vulnerabilities
- CVE-2026-77946 — Critical (CVSS 10.0): A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function…
- CVE-2026-76008 — Critical (CVSS 10.0): A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file…
- CVE-2026-75784 — Critical (CVSS 10.0): A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of…
- CVE-2026-74843 — Critical (CVSS 10.0): A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function…
- CVE-2026-16367 — Critical (CVSS 10.0): Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox…
- CVE-2026-2778 — Critical (CVSS 10.0): Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in…