XFree86 3.3.x and 4.0 allows a user to cause a denial of service via a negative counter value in a malformed TCP packet that is sent to port 6000.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2000-0452
http://www.securityfocus.com/bid/1235
http://archives.neohapsis.com/archives/bugtraq/2000-05/0223.html