Debian Xorg-Server vulnerabilities
123 known vulnerabilities affecting debian/xorg-server.
Total CVEs
123
CISA KEV
0
Public exploits
5
Exploited in wild
2
Severity breakdown
CRITICAL20HIGH55MEDIUM35LOW13
Vulnerabilities
Page 7 of 7
CVE-2011-4028P4LOWCVSS 1.2fixed in xorg-server 2:1.11.1.901-2 (bookworm)2011
CVE-2011-4028 [LOW] CVE-2011-4028: xorg-server - The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows loca...
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a symlink attack on a temporary lock file, which is handled differently if the file exists.
Scope: local
bookworm: resolved (fixed in 2:1.11.1.901-2)
bullseye: resolved (fixed in 2:1.11.1.901-2)
forky: resolved (fixed in 2:1.11.1
debian
CVE-2006-1526P4LOWCVSS 2.1fixed in xorg-server 1:1.0.2-8 (bookworm)2006
CVE-2006-1526 [LOW] CVE-2006-1526: xorg-server - Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up t...
Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause a denial of service (crash), as demonstrated by the (1) XRenderCompositeTriStrip and (2) XRenderCompositeTriFan requests in the rendertest from XCB xcb/xcb-demo, which leads to an incorrect memory allocation due to a typo in an expression that uses a "&" inst
debian
CVE-2013-1940P4LOWCVSS 2.1fixed in xorg-server 2:1.12.4-6 (bookworm)2013
CVE-2013-1940 [LOW] CVE-2013-1940: xorg-server - X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict ...
X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain sensitive information, as demonstrated by reading passwords from a tty.
Scope: local
bookworm: resolved (fixed in 2:1.12.4-6)
bullseye: resolved (fixed in 2:1.12.4-6)
for
debian
← Previous7 / 7