Total vulnerabilities in the database
misc.c in splitvt 1.6.6 and earlier does not drop group privileges before executing xprop, which allows local users to gain privileges.
CVSS v2:
CWEs: