📦

gdm

Vendor: gnome

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 1 Remote Access
Total CVEs 35 Total Indexed
Avg. EPSS 1.97% Exploit Prob.
Latest CVE CVE-2011-1709 Jun 14

Security Vulnerability Index

Page 2 / 4
5.0 CVSS

The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.

EPSS: 1.47%
2.1 CVSS

GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file.

EPSS: 0.37%
5.0 CVSS
CVE-2000-0504
Exploit Found

libICE in XFree86 allows remote attackers to cause a denial of service by specifying a large value which is not properly checked by the SKIP_STRING macro.

EPSS: 3.28%
10.0 CVSS
CVE-2000-0491
Exploit Found

Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request.

EPSS: 17.78%
2.1 CVSS

Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.

EPSS: 0.42%