X.org
x.org
168 CVEs • 31 products
Products (31)
Click to collapseToggle
Products (31)
Click to collapse
CVEs (168)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confi...Show more |
2Redhat X.org2Enterprise Linux X ServerJun 17, 2026 Dec 15, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and i...Show more |
3Canonical RedhatX.org3Enterprise Linux Ubuntu LinuxX ServerJun 17, 2026 Sep 15, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data...Show more |
3Canonical RedhatX.org3Enterprise Linux Ubuntu LinuxX ServerJun 17, 2026 Sep 15, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data...Show more |
3Canonical RedhatX.org3Enterprise Linux Ubuntu LinuxX ServerJun 17, 2026 Sep 15, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerabili...Show more |
2Canonical X.org2Ubuntu Linux X ServerJun 17, 2026 Sep 15, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data conf...Show more |
2Fedoraproject X.org2Fedora Libx11Jun 17, 2026 Sep 11, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases, result in arbitrary co...Show more |
3Canonical DebianX.org3Debian Linux Ubuntu LinuxX ServerJun 17, 2026 Aug 5, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASL...Show more |
4Canonical FedoraprojectOpensuse+1 more4Fedora LeapLibx11+1 moreJun 17, 2026 Aug 5, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM...Show more |
"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sending ct.c_char 1000 times, an attacker can cause a denial of service (application crash) or possibly ha...Show more |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreAug 29, 2025 Oct 25, 2018 N/A· v4 6.6 MEDIUM· v3 7.2 HIGH· v2 A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via ph...Show more |
3Canonical DebianX.org3Debian Linux Libx11Ubuntu LinuxNov 21, 2024 Aug 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resulting in an out-of-bounds write (of up to 128 bytes), leading to DoS or...Show more |
5Canonical DebianFedoraproject+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Aug 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibx11+1 moreNov 21, 2024 Aug 24, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overflows, causing a variable to be set to NULL that will be freed later on,...Show more |
2Redhat X.org7Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Jul 27, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to...Show more |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jul 27, 2018 N/A· v4 7.0 HIGH· v3 1.9 LOW· v2 It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since mos...Show more |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |