cbcvebase.

Debian Xorg-Server vulnerabilities

123 known vulnerabilities affecting debian/xorg-server.

Total CVEs
123
CISA KEV
0
Public exploits
5
Exploited in wild
2
Severity breakdown
CRITICAL20HIGH55MEDIUM35LOW13

Vulnerabilities

Page 3 of 7
CVE-2024-9632P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u8 (bookworm)2024
CVE-2024-9632 [HIGH] CVE-2024-9632: xorg-server - A flaw was found in the X.org server. Due to improperly tracked allocation size ... A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payload, leading to denial of service or local privilege escalation in distributions where the X.org server is run with root privileges. Scope: local bookworm: resolved (fix
debian
CVE-2006-6102P3CRITICALCVSS 10.0fixed in xorg-server 2:1.1.1-15 (bookworm)2006
CVE-2006-6102 [CRITICAL] CVE-2006-6102: xorg-server - Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X... Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of unspecified data structures. Scope: local bookworm: resolved (fixed in 2:1.1.1-15) bullseye: res
debian
CVE-2021-3472P3HIGHCVSS 7.8fixed in xorg-server 2:1.20.11-1 (bookworm)2021
CVE-2021-3472 [HIGH] CVE-2021-3472: xorg-server - A flaw was found in xorg-x11-server in versions before 1.20.11. An integer under... A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead to a local privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Scope: local bookworm: resolved (fixed in 2:1.20.11-1) bullseye: resolved (fixed in 2:1.20.11-1)
debian
CVE-2007-5760P3CRITICALCVSS 9.3fixed in xorg-server 2:1.4.1~git20080105-2 (bookworm)2007
CVE-2007-5760 [CRITICAL] CVE-2007-5760: xorg-server - Array index error in the XFree86-Misc extension in X.Org Xserver before 1.4.1 al... Array index error in the XFree86-Misc extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via a PassMessage request containing a large array index. Scope: local bookworm: resolved (fixed in 2:1.4.1~git20080105-2) bullseye: resolved (fixed in 2:1.4.1~git20080105-2) forky: resolved (fixed in 2:1.4.1~git20080105-2)
debian
CVE-2020-14346P3HIGHCVSS 7.8fixed in xorg-server 2:1.20.9-1 (bookworm)2020
CVE-2020-14346 [HIGH] CVE-2020-14346: xorg-server - A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X... A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Scope: local bookworm: resolved (fixed in 2:1.20.9-1) bullseye: reso
debian
CVE-2023-5367P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u2 (bookworm)2023
CVE-2023-5367 [HIGH] CVE-2023-5367: xorg-server - A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs d... A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service. Scope: loc
debian
CVE-2020-14345P3HIGHCVSS 7.8fixed in xorg-server 2:1.20.9-1 (bookworm)2020
CVE-2020-14345 [HIGH] CVE-2020-14345: xorg-server - A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds... A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Scope: local bookworm: resolved (fixed in 2:1.20.9-1) bullseye: resolved (fixed in 2:1
debian
CVE-2021-4009P3HIGHCVSS 7.8fixed in xorg-server 2:1.20.13-3 (bookworm)2021
CVE-2021-4009 [HIGH] CVE-2021-4009: xorg-server - A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14... A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcXFixesCreatePointerBarrier function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Scope: local bookworm: resolved (fixed in 2:1.20.13-3) bullseye: resolved (fixed in 2
debian
CVE-2021-4010P3HIGHCVSS 7.8fixed in xorg-server 2:1.20.13-3 (bookworm)2021
CVE-2021-4010 [HIGH] CVE-2021-4010: xorg-server - A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14... A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSuspend function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Scope: local bookworm: resolved (fixed in 2:1.20.13-3) bullseye: resolved (fixed in 2:1.20.11
debian
CVE-2021-4008P3HIGHCVSS 7.8fixed in xorg-server 2:1.20.13-3 (bookworm)2021
CVE-2021-4008 [HIGH] CVE-2021-4008: xorg-server - A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14... A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Scope: local bookworm: resolved (fixed in 2:1.20.13-3) bullseye: resolved (fixed in 2:1.20
debian
CVE-2021-4011P3HIGHCVSS 7.8fixed in xorg-server 2:1.20.13-3 (bookworm)2021
CVE-2021-4011 [HIGH] CVE-2021-4011: xorg-server - A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14... A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Scope: local bookworm: resolved (fixed in 2:1.20.13-3) bullseye: resolved (fixed in 2:1.20.11-1+de
debian
CVE-2025-26597P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u9 (bookworm)2025
CVE-2025-26597 [HIGH] CVE-2025-26597: xorg-server - A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey()... A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zero value of groups, this will cause a buffer overflow because the key actions are of the wrong size. Scope: local bookworm: reso
debian
CVE-2025-26596P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u9 (bookworm)2025
CVE-2025-26596 [HIGH] CVE-2025-26596: xorg-server - A heap overflow flaw was found in X.Org and Xwayland. The computation of the len... A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 2:21.1.7-3+deb12u9) bullseye: resolved (fixed in 2:1.20.11-1+deb11u15) forky: resolved (fixed in 2:21.1.16-1) sid: reso
debian
CVE-2008-2360P3CRITICALCVSS 9.0fixed in xorg-server 2:1.4.1~git20080517-2 (bookworm)2008
CVE-2008-2360 [CRITICAL] CVE-2008-2360: xorg-server - Integer overflow in the AllocateGlyph function in the Render extension in the X ... Integer overflow in the AllocateGlyph function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to execute arbitrary code via unspecified request fields that are used to calculate a heap buffer size, which triggers a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 2:1.4.1~git20080517-2) bulls
debian
CVE-2022-49737P3HIGHCVSS 7.7fixed in xorg-server 2:21.1.16-1.1 (forky)2022
CVE-2022-49737 [HIGH] CVE-2022-49737: xorg-server - In X.Org X server 20.11 through 21.1.16, when a client application uses easystro... In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread modifies various data structures used by the input thread without acquiring a lock, aka a race condition. In particular, AttachDevice in dix/devices.c does not acquire an input lock. Scope: local bookworm: open bullseye: open forky: resolved (fi
debian
CVE-2008-1377P3CRITICALCVSS 9.0fixed in xorg-server 2:1.4.1~git20080517-2 (bookworm)2008
CVE-2008-1377 [CRITICAL] CVE-2008-1377: xorg-server - The (1) SProcRecordCreateContext and (2) SProcRecordRegisterClients functions in... The (1) SProcRecordCreateContext and (2) SProcRecordRegisterClients functions in the Record extension and the (3) SProcSecurityGenerateAuthorization function in the Security extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via requests with crafted length values that specify an arbitrary number of bytes
debian
CVE-2025-62230P3HIGHCVSS 7.3fixed in xorg-server 2:21.1.7-3+deb12u11 (bookworm)2025
CVE-2025-62230 [HIGH] CVE-2025-62230: xorg-server - A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when ha... A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect. Scope: local bookworm: resolved (fixed in 2:21
debian
CVE-2007-1003P3MEDIUMCVSS 9.0fixed in xorg-server 2:1.1.1-21 (bookworm)2007
CVE-2007-1003 [CRITICAL] CVE-2007-1003: xorg-server - Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the X... Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, allows remote authenticated users to execute arbitrary code via a large expression, which results in memory corruption. Scope: local bookworm: resolved (fixed in 2:1.1.1-21) bullseye:
debian
CVE-2022-2319P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.4-1 (bookworm)2022
CVE-2022-2319 [HIGH] CVE-2022-2319: xorg-server - A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur... A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur in the ProcXkbSetGeometry function due to improper validation of the request length. Scope: local bookworm: resolved (fixed in 2:21.1.4-1) bullseye: resolved (fixed in 2:1.20.11-1+deb11u2) forky: resolved (fixed in 2:21.1.4-1) sid: resolved (fixed in 2:21.1.4-1) trixie: resolved (fixe
debian
CVE-2020-14360P3HIGHCVSS 7.8fixed in xorg-server 2:1.20.10-1 (bookworm)2020
CVE-2020-14360 [HIGH] CVE-2020-14360: xorg-server - A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds ac... A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Scope: local bookworm: resolved (fixed in 2:1.20.10-1) bullseye: resolved (fixed in 2:1
debian
Debian Xorg-Server vulnerabilities | cvebase