cbcvebase.

Debian Xorg-Server vulnerabilities

123 known vulnerabilities affecting debian/xorg-server.

Total CVEs
123
CISA KEV
0
Public exploits
5
Exploited in wild
2
Severity breakdown
CRITICAL20HIGH55MEDIUM35LOW13

Vulnerabilities

Page 4 of 7
CVE-2025-26594P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u9 (bookworm)2025
CVE-2025-26594 [HIGH] CVE-2025-26594: xorg-server - A use-after-free flaw was found in X.Org and Xwayland. The root cursor is refere... A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed memory and causes a use-after-free. Scope: local bookworm: resolved (fixed in 2:21.1.7-3+deb12u9) bullseye: resolved (fixed in 2:1.20.11-1+deb11u15) forky: resolved (f
debian
CVE-2025-26600P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u9 (bookworm)2025
CVE-2025-26600 [HIGH] CVE-2025-26600: xorg-server - A use-after-free flaw was found in X.Org and Xwayland. When a device is removed ... A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free. Scope: local bookworm: resolved (fixed in 2:21.1.7-3+deb12u9) bullseye: resolved (fixed in 2:1.20.11-1+deb11u15) forky: resolved (fixed in 2:21.1.
debian
CVE-2025-49179P3HIGHCVSS 7.3fixed in xorg-server 2:21.1.7-3+deb12u10 (bookworm)2025
CVE-2025-49179 [HIGH] CVE-2025-49179: xorg-server - A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients... A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length checks. Scope: local bookworm: resolved (fixed in 2:21.1.7-3+deb12u10) bullseye: resolved (fixed in 2:1.20.11-1+deb11u16) forky: resolved (fixed in 2:21.1.16-1.2) si
debian
CVE-2008-0006P3HIGHCVSS 7.5fixed in libxfont 1:1.3.1-2 (bookworm)2008
CVE-2008-0006 [HIGH] CVE-2008-0006: libxfont - Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXf... Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table. Scope: local bookworm: resolved (fixed in 1:1.3.1-2) bullsey
debian
CVE-2020-14361P3HIGHCVSS 7.8fixed in xorg-server 2:1.20.9-1 (bookworm)2020
CVE-2020-14361 [HIGH] CVE-2020-14361: xorg-server - A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer under... A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Scope: local bookworm: resolved (fixed in 2:1.20.9-1) bullseye: resolved (fixed i
debian
CVE-2020-14362P3HIGHCVSS 7.8fixed in xorg-server 2:1.20.9-1 (bookworm)2020
CVE-2020-14362 [HIGH] CVE-2020-14362: xorg-server - A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer under... A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Scope: local bookworm: resolved (fixed in 2:1.20.9-1) bullseye: resolved (fixed i
debian
CVE-2025-26601P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u9 (bookworm)2025
CVE-2025-26601 [HIGH] CVE-2025-26601: xorg-server - A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, t... A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventually, SyncInitTrigger() is called. If one of the changes triggers an error, the function will return early, not adding the new sync object, possibly causing a use-after
debian
CVE-2024-31080P3HIGHCVSS 7.3fixed in xorg-server 2:21.1.7-3+deb12u7 (bookworm)2024
CVE-2024-31080 [HIGH] CVE-2024-31080: xorg-server - A heap-based buffer over-read vulnerability was found in the X.org server's Proc... A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attac
debian
CVE-2024-31081P3HIGHCVSS 7.3fixed in xorg-server 2:21.1.7-3+deb12u7 (bookworm)2024
CVE-2024-31081 [HIGH] CVE-2024-31081: xorg-server - A heap-based buffer over-read vulnerability was found in the X.org server's Proc... A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attac
debian
CVE-2025-62229P3HIGHCVSS 7.3fixed in xorg-server 2:21.1.7-3+deb12u11 (bookworm)2025
CVE-2025-62229 [HIGH] CVE-2025-62229: xorg-server - A flaw was found in the X.Org X server and Xwayland when processing X11 Present ... A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service. Sco
debian
CVE-2007-2437P4LOWCVSS 5.5PoCfixed in xorg-server 2:1.3.0.0.dfsg-4 (bookworm)2007
CVE-2007-2437 [MEDIUM] CVE-2007-2437: xorg-server - The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, wit... The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to cause a denial of service (daemon crash) via crafted values to the (1) XRenderCompositeTrapezoids and (2) XRenderAddTraps functions, which trigger a divide-by-zero error. Scope: local bookworm: resolved (fixed in 2:1.3
debian
CVE-2014-8098P3MEDIUMCVSS 6.5fixed in xorg-server 2:1.16.2.901-1 (bookworm)2014
CVE-2014-8098 [MEDIUM] CVE-2014-8098: xorg-server - The GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, ... The GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) __glXDisp_Render, (2) __glXDisp_RenderLarge, (3)
debian
CVE-2025-26599P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u9 (bookworm)2025
CVE-2025-26599 [HIGH] CVE-2025-26599: xorg-server - An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The ... An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc error without validating the window tree marked just before, which leaves the validated data partly initialized and the use of an uninitialized po
debian
CVE-2024-0409P3HIGHCVSS 7.8fixed in xorg-server 2:21.1.7-3+deb12u5 (bookworm)2024
CVE-2024-0409 [HIGH] CVE-2024-0409: xorg-server - A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwaylan... A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX context. Scope: local bookworm: resolved (fixed in 2:21.1.7-3+deb12u5) bullseye: resolved (fixed in 2:1.20.11-1+deb11u11)
debian
CVE-2020-25712P3HIGHCVSS 7.8fixed in xorg-server 2:1.20.10-1 (bookworm)2020
CVE-2020-25712 [HIGH] CVE-2020-25712: xorg-server - A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in Xk... A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Scope: local bookworm: resolved (fixed in 2:1.20.10-1) bullseye: resolved (fixed in 2:1.20.10-1) forky:
debian
CVE-2007-6429P3CRITICALCVSS 9.3fixed in xorg-server 2:1.4.1~git20080105-2 (bookworm)2007
CVE-2007-6429 [CRITICAL] CVE-2007-6429: xorg-server - Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent... Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in managem
debian
CVE-2024-31082P3HIGHCVSS 7.3fixed in xorg-server 2:21.1.7-3+deb12u7 (bookworm)2024
CVE-2024-31082 [HIGH] CVE-2024-31082: xorg-server - A heap-based buffer over-read vulnerability was found in the X.org server's Proc... A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an atta
debian
CVE-2012-2118P3CRITICALCVSS 10.0fixed in xorg-server 2:1.12.1.902-1 (bookworm)2012
CVE-2012-2118 [CRITICAL] CVE-2012-2118: xorg-server - Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.... Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in an input device name. Scope: local bookworm: resolved (fixed in 2:1.12.1.902-1) bullseye: resolved (fixed in 2:1.12.1.902-1) forky: resolved (fixed in 2:1.1
debian
CVE-2014-8095P3MEDIUMCVSS 6.5fixed in xorg-server 2:1.16.2.901-1 (bookworm)2014
CVE-2014-8095 [MEDIUM] CVE-2014-8095: xorg-server - The XInput extension in X.Org X Window System (aka X11 or X) X11R4 and X.Org Ser... The XInput extension in X.Org X Window System (aka X11 or X) X11R4 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) SProcXChangeDeviceControl, (2) ProcXChangeDeviceControl, (3)
debian
CVE-2014-8099P3MEDIUMCVSS 6.5fixed in xorg-server 2:1.16.2.901-1 (bookworm)2014
CVE-2014-8099 [MEDIUM] CVE-2014-8099: xorg-server - The XVideo extension in XFree86 4.0.0, X.Org X Window System (aka X11 or X) X11R... The XVideo extension in XFree86 4.0.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) SProcXvQueryExtension, (2) SProcXvQueryAdap
debian
Debian Xorg-Server vulnerabilities | cvebase