cbcvebase.
CVE-2020-14346
published 2020-09-15

CVE-2020-14346: A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access…

PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.63%
46.5th percentile
A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected

14 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debianxorg-server< xorg-server 2:1.20.9-1 (bookworm)xorg-server 2:1.20.9-1 (bookworm)
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
x.orgx_server< 1.20.91.20.9
x.orgxorg-server>= 0 < 2:1.20.9-12:1.20.9-1
x.orgxorg-server>= 0 < 2:1.20.9-12:1.20.9-1
x.orgxorg-server>= 0 < 2:1.20.9-12:1.20.9-1
x.orgxorg-server>= 0 < 2:1.20.9-12:1.20.9-1
x.orgxorg-server>= 0 < 2:1.18.4-0ubuntu0.92:1.18.4-0ubuntu0.9
x.orgxorg-server>= 0 < 2:1.19.6-1ubuntu4.52:1.19.6-1ubuntu4.5
x.orgxorg-server>= 0 < 2:1.20.8-2ubuntu2.32:1.20.8-2ubuntu2.3
x.orgxorg-server>= 0 < 2:1.15.1-0ubuntu2.11+esm22:1.15.1-0ubuntu2.11+esm2

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.