cbcvebase.

Debian Xorg-Server vulnerabilities

123 known vulnerabilities affecting debian/xorg-server.

Total CVEs
123
CISA KEV
0
Public exploits
5
Exploited in wild
2
Severity breakdown
CRITICAL20HIGH55MEDIUM35LOW13

Vulnerabilities

Page 1 of 7
CVE-2018-14665P1MEDIUMCVSS 6.6ExploitedPoCRansomwarefixed in xorg-server 2:1.20.3-1 (bookworm)2018
CVE-2018-14665 [MEDIUM] CVE-2018-14665: xorg-server - A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check... A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges. Scope: local bookworm: resolved (fixed in 2:1.20.3-1
debian
CVE-2023-1393P3HIGHCVSS 7.8Exploitedfixed in xorg-server 2:21.1.7-2 (bookworm)2023
CVE-2023-1393 [HIGH] CVE-2023-1393: xorg-server - A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to lo... A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later. Scope: local bookworm: resolved (fixed in 2:21.1.7-2) bul
debian
CVE-2022-46341P3HIGHCVSS 8.8fixed in xorg-server 2:21.1.5-1 (bookworm)2022
CVE-2022-46341 [HIGH] CVE-2022-46341: xorg-server - A vulnerability was found in X.Org. This security flaw occurs because the handle... A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveUngrab request accesses out-of-bounds memory when invoked with a high keycode or button code. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions. Scope: local
debian
CVE-2022-46340P3HIGHCVSS 8.8fixed in xorg-server 2:21.1.5-1 (bookworm)2022
CVE-2022-46340 [HIGH] CVE-2022-46340: xorg-server - A vulnerability was found in X.Org. This security flaw occurs becuase the swap h... A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of the XTest extension may corrupt the stack if GenericEvents with lengths larger than 32 bytes are sent through a the XTestFakeInput request. This issue can lead to local privileges elevation on systems where the X server is running privileged a
debian
CVE-2022-46343P3HIGHCVSS 8.8fixed in xorg-server 2:21.1.5-1 (bookworm)2022
CVE-2022-46343 [HIGH] CVE-2022-46343: xorg-server - A vulnerability was found in X.Org. This security flaw occurs because the handle... A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions. Scope: local bookworm: resolved (fixe
debian
CVE-2017-12186P3CRITICALCVSS 9.8fixed in xorg-server 2:1.19.5-1 (bookworm)2017
CVE-2017-12186 [CRITICAL] CVE-2017-12186: xorg-server - xorg-x11-server before 1.19.5 was missing length validation in X-Resource extens... xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. Scope: local bookworm: resolved (fixed in 2:1.19.5-1) bullseye: resolved (fixed in 2:1.19.5-1) forky: resolved (fixed in 2:1.19.5-1) sid: resolved (fixed in 2:1.19.5-1) trixie: resolved
debian
CVE-2017-12185P3CRITICALCVSS 9.8fixed in xorg-server 2:1.19.5-1 (bookworm)2017
CVE-2017-12185 [CRITICAL] CVE-2017-12185: xorg-server - xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER ... xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. Scope: local bookworm: resolved (fixed in 2:1.19.5-1) bullseye: resolved (fixed in 2:1.19.5-1) forky: resolved (fixed in 2:1.19.5-1) sid: resolved (fixed in 2:1.19.5-1) trixie: re
debian
CVE-2017-12181P3CRITICALCVSS 9.8fixed in xorg-server 2:1.19.5-1 (bookworm)2017
CVE-2017-12181 [CRITICAL] CVE-2017-12181: xorg-server - xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA exten... xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. Scope: local bookworm: resolved (fixed in 2:1.19.5-1) bullseye: resolved (fixed in 2:1.19.5-1) forky: resolved (fixed in 2:1.19.5-1) sid: resolved (fixed in 2:1.19.5-1) trixie: resolve
debian
CVE-2017-12183P3CRITICALCVSS 9.8fixed in xorg-server 2:1.19.5-1 (bookworm)2017
CVE-2017-12183 [CRITICAL] CVE-2017-12183: xorg-server - xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension ... xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. Scope: local bookworm: resolved (fixed in 2:1.19.5-1) bullseye: resolved (fixed in 2:1.19.5-1) forky: resolved (fixed in 2:1.19.5-1) sid: resolved (fixed in 2:1.19.5-1) trixie: resolved (fi
debian
CVE-2017-12180P3CRITICALCVSS 9.8fixed in xorg-server 2:1.19.5-1 (bookworm)2017
CVE-2017-12180 [CRITICAL] CVE-2017-12180: xorg-server - xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeEx... xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. Scope: local bookworm: resolved (fixed in 2:1.19.5-1) bullseye: resolved (fixed in 2:1.19.5-1) forky: resolved (fixed in 2:1.19.5-1) sid: resolved (fixed in 2:1.19.5-1) trixie: reso
debian
CVE-2017-12182P3CRITICALCVSS 9.8fixed in xorg-server 2:1.19.5-1 (bookworm)2017
CVE-2017-12182 [CRITICAL] CVE-2017-12182: xorg-server - xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI exten... xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. Scope: local bookworm: resolved (fixed in 2:1.19.5-1) bullseye: resolved (fixed in 2:1.19.5-1) forky: resolved (fixed in 2:1.19.5-1) sid: resolved (fixed in 2:1.19.5-1) trixie: resolve
debian
CVE-2017-12184P3CRITICALCVSS 9.8fixed in xorg-server 2:1.19.5-1 (bookworm)2017
CVE-2017-12184 [CRITICAL] CVE-2017-12184: xorg-server - xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extensio... xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. Scope: local bookworm: resolved (fixed in 2:1.19.5-1) bullseye: resolved (fixed in 2:1.19.5-1) forky: resolved (fixed in 2:1.19.5-1) sid: resolved (fixed in 2:1.19.5-1) trixie: resolved (
debian
CVE-2017-12176P3CRITICALCVSS 9.8fixed in xorg-server 2:1.19.5-1 (bookworm)2017
CVE-2017-12176 [CRITICAL] CVE-2017-12176: xorg-server - xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstabli... xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X server to crash or possibly execute arbitrary code. Scope: local bookworm: resolved (fixed in 2:1.19.5-1) bullseye: resolved (fixed in 2:1.19.5-1) forky: resolved (fixed in 2:1.19.5-1) sid: resolved (fixed in 2:1.19.5-1
debian
CVE-2022-46344P3HIGHCVSS 8.8fixed in xorg-server 2:21.1.5-1 (bookworm)2022
CVE-2022-46344 [HIGH] CVE-2022-46344: xorg-server - A vulnerability was found in X.Org. This security flaw occurs because the handle... A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclosure. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X f
debian
CVE-2017-12187P3CRITICALCVSS 9.8fixed in xorg-server 2:1.19.5-1 (bookworm)2017
CVE-2017-12187 [CRITICAL] CVE-2017-12187: xorg-server - xorg-x11-server before 1.19.5 was missing length validation in RENDER extension ... xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. Scope: local bookworm: resolved (fixed in 2:1.19.5-1) bullseye: resolved (fixed in 2:1.19.5-1) forky: resolved (fixed in 2:1.19.5-1) sid: resolved (fixed in 2:1.19.5-1) trixie: resolved (fi
debian
CVE-2017-12178P3CRITICALCVSS 9.8fixed in xorg-server 2:1.19.5-1 (bookworm)2017
CVE-2017-12178 [CRITICAL] CVE-2017-12178: xorg-server - xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierar... xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash or possibly execute arbitrary code. Scope: local bookworm: resolved (fixed in 2:1.19.5-1) bullseye: resolved (fixed in 2:1.19.5-1) forky: resolved (fixed in 2:1.19.5-1) sid: resolved (fixed in 2:1.19.5-1) trixie:
debian
CVE-2023-6816P3CRITICALCVSS 9.8fixed in xorg-server 2:21.1.7-3+deb12u5 (bookworm)2023
CVE-2023-6816 [CRITICAL] CVE-2023-6816: xorg-server - A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer r... A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used. Scope: local boo
debian
CVE-2017-10971P3HIGHCVSS 8.8fixed in xorg-server 2:1.19.3-2 (bookworm)2017
CVE-2017-10971 [HIGH] CVE-2017-10971: xorg-server - In the X.Org X server before 2017-06-19, a user authenticated to an X Session co... In the X.Org X server before 2017-06-19, a user authenticated to an X Session could crash or execute code in the context of the X Server by exploiting a stack overflow in the endianness conversion of X Events. Scope: local bookworm: resolved (fixed in 2:1.19.3-2) bullseye: resolved (fixed in 2:1.19.3-2) forky: resolved (fixed in 2:1.19.3-2) sid: resolved (fixed
debian
CVE-2017-12177P3CRITICALCVSS 9.8fixed in xorg-server 2:1.19.5-1 (bookworm)2017
CVE-2017-12177 [CRITICAL] CVE-2017-12177: xorg-server - xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVi... xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X server to crash or possibly execute arbitrary code. Scope: local bookworm: resolved (fixed in 2:1.19.5-1) bullseye: resolved (fixed in 2:1.19.5-1) forky: resolved (fixed in 2:1.19.5-1) sid: resolved (fixed in 2:1.19.5-1) tr
debian
CVE-2017-12179P3CRITICALCVSS 9.8fixed in xorg-server 2:1.19.5-1 (bookworm)2017
CVE-2017-12179 [CRITICAL] CVE-2017-12179: xorg-server - xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBar... xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to cause X server to crash or possibly execute arbitrary code. Scope: local bookworm: resolved (fixed in 2:1.19.5-1) bullseye: resolved (fixed in 2:1.19.5-1) forky: resolved (fixed in 2:1.19.5-1) sid: resolved (fixed in 2:1
debian
Debian Xorg-Server vulnerabilities | cvebase