Latest CVE Feed
-
9.8
CRITICALCVE-2017-12184
xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.... Read more
- EPSS Score: %0.84
- Published: Jan. 24, 2018
- Modified: Aug. 29, 2025
-
7.8
HIGHCVE-2020-14346
A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and i... Read more
- EPSS Score: %0.08
- Published: Sep. 15, 2020
- Modified: Aug. 29, 2025
-
7.8
HIGHCVE-2020-14361
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as w... Read more
- EPSS Score: %0.10
- Published: Sep. 15, 2020
- Modified: Aug. 29, 2025
-
7.8
HIGHCVE-2020-14362
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as w... Read more
- EPSS Score: %0.10
- Published: Sep. 15, 2020
- Modified: Aug. 29, 2025
-
7.2
HIGHCVE-2018-14665
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their pr... Read more
- EPSS Score: %7.31
- Published: Oct. 25, 2018
- Modified: Aug. 29, 2025
-
6.5
MEDIUMCVE-2014-8096
The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X) X11R6.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or ... Read more
- EPSS Score: %1.01
- Published: Dec. 10, 2014
- Modified: Aug. 29, 2025
-
5.5
MEDIUMCVE-2020-14347
A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before versio... Read more
- EPSS Score: %0.02
- Published: Aug. 05, 2020
- Modified: Aug. 29, 2025
-
6.5
MEDIUMCVE-2014-8102
The SProcXFixesSelectSelectionInput function in the XFixes extension in X.Org X Window System (aka X11 or X) X11R6.8.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-boun... Read more
- EPSS Score: %1.12
- Published: Dec. 10, 2014
- Modified: Aug. 29, 2025
-
6.5
MEDIUMCVE-2014-8100
The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly exec... Read more
- EPSS Score: %1.30
- Published: Dec. 10, 2014
- Modified: Aug. 29, 2025
-
6.5
MEDIUMCVE-2014-8098
The GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute a... Read more
- EPSS Score: %1.01
- Published: Dec. 10, 2014
- Modified: Aug. 29, 2025
-
6.5
MEDIUMCVE-2014-8092
Multiple integer overflows in X.Org X Window System (aka X11 or X) X11R1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted re... Read more
- EPSS Score: %1.29
- Published: Dec. 10, 2014
- Modified: Aug. 29, 2025
-
4.3
MEDIUMCVE-2014-8091
X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver and xorg-server) before 1.16.3, when using SUN-DES-1 (Secure RPC) authentication credentials, does not check the return value of a malloc call, which allows remote attackers to caus... Read more
- EPSS Score: %6.31
- Published: Dec. 10, 2014
- Modified: Aug. 29, 2025
-
6.5
MEDIUMCVE-2014-8101
The RandR extension in XFree86 4.2.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execu... Read more
- EPSS Score: %1.27
- Published: Dec. 10, 2014
- Modified: Aug. 29, 2025
-
6.4
MEDIUMCVE-2015-0255
X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string length value in a XkbSetGeometry reques... Read more
- EPSS Score: %8.19
- Published: Feb. 13, 2015
- Modified: Aug. 29, 2025
-
7.5
HIGHCVE-2015-3418
The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service (divide-by-zero and crash) via a zero-height PutImage request.... Read more
- EPSS Score: %0.50
- Published: Dec. 13, 2016
- Modified: Aug. 29, 2025
-
6.5
MEDIUMCVE-2014-8099
The XVideo extension in XFree86 4.0.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly exec... Read more
- EPSS Score: %4.56
- Published: Dec. 10, 2014
- Modified: Aug. 29, 2025
-
8.8
HIGHCVE-2017-10971
In the X.Org X server before 2017-06-19, a user authenticated to an X Session could crash or execute code in the context of the X Server by exploiting a stack overflow in the endianness conversion of X Events.... Read more
- EPSS Score: %1.96
- Published: Jul. 06, 2017
- Modified: Aug. 29, 2025
-
9.8
CRITICALCVE-2017-12178
xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.... Read more
- EPSS Score: %0.95
- Published: Jan. 24, 2018
- Modified: Aug. 29, 2025
-
9.8
CRITICALCVE-2017-12183
xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.... Read more
- EPSS Score: %0.95
- Published: Jan. 24, 2018
- Modified: Aug. 29, 2025
-
9.8
CRITICALCVE-2017-12182
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.... Read more
- EPSS Score: %0.95
- Published: Jan. 24, 2018
- Modified: Aug. 29, 2025