Vulnerability Database

310,450

Total vulnerabilities in the database

CVE-2006-3739

Integer overflow in the CIDAFM function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted Adobe Font Metrics (AFM) files with a modified number of character metrics (StartCharMetrics), which leads to a heap-based buffer overflow.

  • Published: Sep 13, 2006
  • Updated: Nov 9, 2025
  • CVE: CVE-2006-3739
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 7.2
  • AV:L/AC:L/Au:N/C:C/I:C/A:C

No CWE or OWASP classifications available.

Software From Fixed in
xfree86_project / xfree86_x - -
x.org / x.org 6.8.2 6.8.2.x