Integer Overflow vulnerability in the RandR extension's RRChangeProviderProperty function. Improper validation allows clients to cause integer overflows during memory allocation calculations, potentially leading to memory corruption.