CVEs (97)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jul 27, 2018 N/A· v4 7.0 HIGH· v3 1.9 LOW· v2 It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since mos...Show more |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerMay 13, 2026 Oct 10, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In X.Org Server (aka xserver and xorg-server) before 1.19.4, a local attacker authenticated to the X server could overflow a global buffer, causing crashes of the X server or potentially other problems by injecting large...Show more |
2Debian X.org2Debian Linux X ServerMay 13, 2026 Oct 10, 2017 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 In X.Org Server (aka xserver and xorg-server) before 1.19.4, an attacker authenticated to an X server with the X shared memory extension enabled can cause aborts of the X server or replace shared memory segments of other...Show more |
Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server. |
In the X.Org X server before 2017-06-19, a user authenticated to an X Session could crash or execute code in the context of the X Server by exploiting a stack overflow in the endianness conversion of X Events. |
The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service (divide-by-zero and crash) via a zero-height PutImage request. |
2Opensuse X.org3Opensuse X ServerXorg ServerMay 6, 2026 Jul 1, 2015 N/A· v4 N/A· v3 3.6 LOW· v2 The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving...Show more |
X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string leng...Show more |