AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2006-5397

LOW · CVSS 2.1 EPSS 0.36%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-11-03 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2006-5397
Severity
LOW
CVSS
2.1
EPSS
0.36%

Original Filing — NVD Description

The Xinput module (modules/im/ximcp/imLcIm.c) in X.Org libX11 1.0.2 and 1.0.3 opens a file for reading twice using the same file descriptor, which causes a file descriptor leak that allows local users to read files specified by the XCOMPOSEFILE environment variable via the duplicate file descriptor.