CVE-2013-2005
Last modified
CVE-2013-2005 is a vulnerability of currently unknown severity. X.org libXt 1.1.3 and earlier does not check the return value of the XGetWindowProperty function, which allows X servers to trigger use of an uninitialized pointer and memory corruption via vectors related to the (1) ReqCleanup, (2) HandleSelectionEvents, (3) ReqTimedOut, (4) HandleNormal, and (5) HandleSelectionReplies functions.. EPSS estimates a 2.09% chance of exploitation in the next 30 days.
Description
X.org libXt 1.1.3 and earlier does not check the return value of the XGetWindowProperty function, which allows X servers to trigger use of an uninitialized pointer and memory corruption via vectors related to the (1) ReqCleanup, (2) HandleSelectionEvents, (3) ReqTimedOut, (4) HandleNormal, and (5) HandleSelectionReplies functions.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| X | Libxt | <= 1.1.3 |
| X | Libxt | 1.0.3 |
| X | Libxt | 1.0.4 |
| X | Libxt | 1.0.5 |
| X | Libxt | 1.0.6 |
| X | Libxt | 1.0.7 |
| X | Libxt | 1.0.8 |
| X | Libxt | 1.0.9 |
| X | Libxt | 1.1.1 |
| X | Libxt | 1.1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-2005?
How severe is CVE-2013-2005?
How do I fix CVE-2013-2005?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-20005Qool CMS 2.0 RC2 contains a cross-site request forgery vulne…6.9
- CVE-2013-20006Qool CMS contains multiple persistent cross-site scripting v…8.7
- CVE-2013-2001Buffer overflow in X.org libXxf86vm 1.1.2 and earlier allows…
- CVE-2013-2002Buffer overflow in X.org libXt 1.1.3 and earlier allows X se…
- CVE-2013-2003Integer overflow in X.org libXcursor 1.1.13 and earlier allo…
- CVE-2013-2004The (1) GetDatabase and (2) _XimParseStringFile functions in…
- CVE-2013-2006OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG m…
- CVE-2013-2007The qemu guest agent in Qemu 1.4.1 and earlier, as used by X…
- CVE-2013-2008WordPress Super Cache Plugin 1.3 has XSS.6.1
- CVE-2013-2009WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Exec…8.8
- CVE-2013-2010WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Cod…9.8
- CVE-2013-2011WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP …8.8
Are you affected by CVE-2013-2005?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
