← Back

X.org

x.org

168 CVEs • 31 products

Products (31)

Click to collapse
Toggle
X Server
x_server
Xwayland
xwayland
X11
x11
Libx11
libx11
X11r6
x11r6
X.org
x.org
Xserver
xserver
Libxi
libxi
Xfree86
xfree86
Libxpm
libxpm
Libxfont
libxfont
Xorg Server
xorg-server
X11r7
x11r7
Xdm
xdm
X Font Server
x_font_server
Libxv
libxv
Libxrandr
libxrandr
Libxrender
libxrender
Xf86dga
xf86dga
Xinit
xinit
Xload
xload
Xterm
xterm
Tog Cup
tog-cup
Evi
evi
Mit Shm
mit-shm
Libxfixes
libxfixes
Libxtst
libxtst
Libxvmc
libxvmc
Libxdmcp
libxdmcp

CVEs (168)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
OracleX.org
3Debian Linux
SolarisX Server
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (c...Show more
Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write.Show less
1X.org
3X11
X ServerXfree86
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple integer overflows in the GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denia...Show more
Multiple integer overflows in the GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to the (1) __glXDisp_ReadPixels, (2) __glXDispSwap_ReadPixels, (3) __glXDisp_GetTexImage, (4) __glXDispSwap_GetTexImage, (5) GetSeparableFilter, (6) GetConvolutionFilter, (7) GetHistogram, (8) GetMinmax, (9) GetColorTable, (10) __glXGetAnswerBuffer, (11) __GLX_GET_ANSWER_BUFFER, (12) __glXMap1dReqSize, (13) __glXMap1fReqSize, (14) Map2Size, (15) __glXMap2dReqSize, (16) __glXMap2fReqSize, (17) __glXImageSize, or (18) __glXSeparableFilter2DReqSize function, which triggers an out-of-bounds read or write.Show less
1X.org
2X11
X Server
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple integer overflows in X.Org X Window System (aka X11 or X) X11R1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly exec...Show more
Multiple integer overflows in X.Org X Window System (aka X11 or X) X11R1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to the (1) ProcPutImage, (2) GetHosts, (3) RegionSizeof, or (4) REQUEST_FIXED_SIZE function, which triggers an out-of-bounds read or write.Show less
1X.org
2X11
X Server
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver and xorg-server) before 1.16.3, when using SUN-DES-1 (Secure RPC) authentication credentials, does not check the return value of a malloc call, wh...Show more
X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver and xorg-server) before 1.16.3, when using SUN-DES-1 (Secure RPC) authentication credentials, does not check the return value of a malloc call, which allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a crafted connection request.Show less
4Canonical
DebianUbuntu+1 more
4Debian Linux
LinuxUbuntu Linux+1 more
Apr 29, 2026
Feb 5, 2014
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restrictions by associating st...Show more
The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restrictions by associating stdin with a file that is misinterpreted as the console TTY.Show less
2X
X.org
2Libxv
Libxv
Apr 29, 2026
Jun 15, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in X.org libXv 1.0.7 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XvQueryPortAttributes function.
1X.org
1Libxi
Apr 29, 2026
Jun 15, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in X.org libXi 1.7.1 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XGetDeviceButtonMapping, (...Show more
Multiple buffer overflows in X.org libXi 1.7.1 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XGetDeviceButtonMapping, (2) XIPassiveGrabDevice, and (3) XQueryDeviceState functions.Show less
1X.org
1Libxi
Apr 29, 2026
Jun 15, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
X.org libXi 1.7.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to an unexpected sign extension in the XListInputDevices function.
1X.org
1Libxi
Apr 29, 2026
Jun 15, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple integer overflows in X.org libXi 1.7.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XGetDeviceControl, (2) XGetFeedbackControl, (3...Show more
Multiple integer overflows in X.org libXi 1.7.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XGetDeviceControl, (2) XGetFeedbackControl, (3) XGetDeviceDontPropagateList, (4) XGetDeviceMotionEvents, (5) XIGetProperty, (6) XIGetSelectedEvents, (7) XGetDeviceProperties, and (8) XListInputDevices functions.Show less
1X.org
1X.org
Apr 29, 2026
Sep 5, 2012
N/A· v4
N/A· v3
8.5 HIGH· v2
The GLX extension in X.Org xserver 1.7.7 allows remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary code via (1) a crafted request that triggers a client swap in glx/glxc...Show more
The GLX extension in X.Org xserver 1.7.7 allows remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary code via (1) a crafted request that triggers a client swap in glx/glxcmdsswap.c; or (2) a crafted length or (3) a negative value in the screen field in a request to glx/glxcmds.c.Show less
1X.org
1X Server
Apr 29, 2026
Jul 3, 2012
N/A· v4
N/A· v3
1.9 LOW· v2
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution per...Show more
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution permission) via a symlink attack on a temporary lock file.Show less
1X.org
1X Server
Apr 29, 2026
Jul 3, 2012
N/A· v4
N/A· v3
1.2 LOW· v2
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a symlink attack on a temporary lock file, which is handled differently if the fil...Show more
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a symlink attack on a temporary lock file, which is handled differently if the file exists.Show less
1X.org
1X11
Apr 29, 2026
May 18, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in an input devic...Show more
Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in an input device name.Show less
2Sun
X.org
3Opensolaris
SolarisX11
Apr 23, 2026
Sep 8, 2009
N/A· v4
N/A· v3
4.0 MEDIUM· v2
xscreensaver (aka Gnome-XScreenSaver) in Sun Solaris 9 and 10, OpenSolaris snv_109 through snv_122, and X11 6.4.1 on Solaris 8 does not properly handle Accessibility support, which allows local users to cause a denial of...Show more
xscreensaver (aka Gnome-XScreenSaver) in Sun Solaris 9 and 10, OpenSolaris snv_109 through snv_122, and X11 6.4.1 on Solaris 8 does not properly handle Accessibility support, which allows local users to cause a denial of service (system hang) by locking the screen and then attempting to launch an Accessibility pop-up window, related to a regression in certain Solaris and OpenSolaris patches.Show less
2Sun
X.org
3Opensolaris
SolarisX11
Apr 23, 2026
Aug 7, 2009
N/A· v4
N/A· v3
4.9 MEDIUM· v2
XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when the Xorg or Xnewt server is used, allows physically proximate attackers to obtain sensitive information by reading popup...Show more
XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when the Xorg or Xnewt server is used, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276.Show less
1X.org
1X11
Apr 23, 2026
Jun 16, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request...Show more
Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size, which triggers a dereference of unmapped memory.Show less
2Sun
X.org
3Solaris Libfont
Solaris LibxfontXserver
Apr 23, 2026
Jan 18, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a la...Show more
Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table.Show less
1X.org
3Evi
Mit ShmXserver
Apr 23, 2026
Jan 18, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amoun...Show more
Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in management of shared memory by the MIT-SHM extension.Show less
1X.org
2Tog Cup
Xserver
Apr 23, 2026
Jan 18, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request containing a 32-bit v...Show more
The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request containing a 32-bit value that is improperly used as an array index.Show less
7Apple
CanonicalDebian+4 more
11Debian Linux
FedoraLinux+8 more
Apr 23, 2026
Jan 18, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerabili...Show more
The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.Show less