Latest CVE Feed
-
9.8
CRITICALCVE-2017-12185
xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.... Read more
- Published: Jan. 24, 2018
- Modified: Aug. 29, 2025
-
9.8
CRITICALCVE-2017-12187
xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.... Read more
- Published: Jan. 24, 2018
- Modified: Aug. 29, 2025
-
7.0
HIGHCVE-2017-2624
It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return a... Read more
- Published: Jul. 27, 2018
- Modified: Aug. 29, 2025
-
9.8
CRITICALCVE-2023-6816
A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the dev... Read more
- Published: Jan. 18, 2024
- Modified: Aug. 29, 2025
-
5.5
MEDIUMCVE-2024-0408
A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another resour... Read more
- Published: Jan. 18, 2024
- Modified: Aug. 29, 2025
-
9.8
CRITICALCVE-2017-12184
xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.... Read more
- Published: Jan. 24, 2018
- Modified: Aug. 29, 2025
-
7.8
HIGHCVE-2020-14346
A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and i... Read more
- Published: Sep. 15, 2020
- Modified: Aug. 29, 2025
-
7.8
HIGHCVE-2020-14361
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as w... Read more
- Published: Sep. 15, 2020
- Modified: Aug. 29, 2025
-
7.8
HIGHCVE-2020-14362
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as w... Read more
- Published: Sep. 15, 2020
- Modified: Aug. 29, 2025
-
7.2
HIGHCVE-2018-14665
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their pr... Read more
- Published: Oct. 25, 2018
- Modified: Aug. 29, 2025
-
6.5
MEDIUMCVE-2014-8096
The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X) X11R6.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or ... Read more
- Published: Dec. 10, 2014
- Modified: Aug. 29, 2025
-
5.5
MEDIUMCVE-2020-14347
A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before versio... Read more
- Published: Aug. 05, 2020
- Modified: Aug. 29, 2025
-
6.5
MEDIUMCVE-2014-8102
The SProcXFixesSelectSelectionInput function in the XFixes extension in X.Org X Window System (aka X11 or X) X11R6.8.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-boun... Read more
- Published: Dec. 10, 2014
- Modified: Aug. 29, 2025
-
6.5
MEDIUMCVE-2014-8100
The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly exec... Read more
- Published: Dec. 10, 2014
- Modified: Aug. 29, 2025
-
6.5
MEDIUMCVE-2014-8098
The GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute a... Read more
- Published: Dec. 10, 2014
- Modified: Aug. 29, 2025
-
6.5
MEDIUMCVE-2014-8092
Multiple integer overflows in X.Org X Window System (aka X11 or X) X11R1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted re... Read more
- Published: Dec. 10, 2014
- Modified: Aug. 29, 2025
-
4.3
MEDIUMCVE-2014-8091
X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver and xorg-server) before 1.16.3, when using SUN-DES-1 (Secure RPC) authentication credentials, does not check the return value of a malloc call, which allows remote attackers to caus... Read more
- Published: Dec. 10, 2014
- Modified: Aug. 29, 2025
-
6.5
MEDIUMCVE-2014-8101
The RandR extension in XFree86 4.2.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execu... Read more
- Published: Dec. 10, 2014
- Modified: Aug. 29, 2025
-
6.4
MEDIUMCVE-2015-0255
X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string length value in a XkbSetGeometry reques... Read more
- Published: Feb. 13, 2015
- Modified: Aug. 29, 2025
-
7.5
HIGHCVE-2015-3418
The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service (divide-by-zero and crash) via a zero-height PutImage request.... Read more
- Published: Dec. 13, 2016
- Modified: Aug. 29, 2025