CVE-2013-1994: Openchrome

Medium severity, CVSS 6.8. EPSS: 1.7% chance of exploitation in the next 30 days.

Multiple integer overflows in X.org libchromeXvMC and libchromeXvMCPro in openChrome 0.3.2 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) uniDRIOpenConnection and (2) uniDRIGetClientDriverName functions.

Affected products

  • Openchrome Openchrome: up to and including 0.3.2
  • X Libchromexvmc: affected versions not specified
  • X Libchromexvmcpro: affected versions not specified

Published 2013-06-15. Last modified 2026-06-16.