X.org
x.org
168 CVEs • 31 products
Products (31)
Click to collapseToggle
Products (31)
Click to collapse
CVEs (168)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The XClientMessageEvent struct used in certain components of X.Org 6.8.2 and earlier, possibly including (1) the X server and (2) Xlib, uses a "long" specifier for elements of the l array, which results in inconsistent s...Show more |
8Altlinux LesstifMandrakesoft+5 more11Alt Linux Enterprise LinuxEnterprise Linux Desktop+8 moreApr 16, 2026 Mar 2, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow. |
6Gentoo LesstifRedhat+3 more6Fedora Core LesstifLinux+3 moreApr 16, 2026 Jan 10, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter...Show more |
4Openbsd SuseX.org+1 more4Openbsd Suse LinuxX11r6+1 moreApr 16, 2026 Oct 20, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to...Show more |
4Openbsd SuseX.org+1 more4Openbsd Suse LinuxX11r6+1 moreApr 16, 2026 Oct 20, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a mal...Show more |
3Gentoo X.orgXfree86 Project3Linux X11r6XdmApr 16, 2026 Aug 18, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions. |
Race condition in xterm allows local users to modify arbitrary files via the logging option. |
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server. |