Debian Xwayland vulnerabilities
46 known vulnerabilities affecting debian/xwayland.
Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH39MEDIUM5LOW1
Vulnerabilities
Page 3 of 3
CVE-2025-49176P3HIGHCVSS 7.3fixed in xorg-server 2:21.1.7-3+deb12u10 (bookworm)2025
CVE-2025-49176 [HIGH] CVE-2025-49176: xorg-server - A flaw was found in the Big Requests extension. The request length is multiplied...
A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check.
Scope: local
bookworm: resolved (fixed in 2:21.1.7-3+deb12u10)
bullseye: resolved (fixed in 2:1.20.11-1+deb11u16)
forky: resolved (fixed in 2:21.1.16-1.3)
sid
debian
CVE-2022-3551P4LOWCVSS 3.5fixed in xorg-server 2:21.1.4-3 (bookworm)2022
CVE-2022-3551 [LOW] CVE-2022-3551: xorg-server - A vulnerability, which was classified as problematic, has been found in X.org Se...
A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by this issue is the function ProcXkbGetKbdByName of the file xkb/xkb.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211052.
Scope: local
bookworm: resolved (fixed in 2:21.1.4-3)
debian
CVE-2025-49177P4MEDIUMCVSS 6.1fixed in xorg-server 2:21.1.7-3+deb12u10 (bookworm)2025
CVE-2025-49177 [MEDIUM] CVE-2025-49177: xorg-server - A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode hand...
A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.
Scope: local
bookworm: resolved (fixed in 2:21.1.7-3+deb12u10)
bullseye: resolved
forky: resolved (fixed in 2:21.1.16-1.2)
sid: resolved (fixed in 2:21.1.16-1.2)
trixie: re
debian
CVE-2025-49175P4MEDIUMCVSS 6.1fixed in xorg-server 2:21.1.7-3+deb12u10 (bookworm)2025
CVE-2025-49175 [MEDIUM] CVE-2025-49175: xorg-server - A flaw was found in the X Rendering extension's handling of animated cursors. If...
A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the server assumes at least one is present, leading to an out-of-bounds read and potential crash.
Scope: local
bookworm: resolved (fixed in 2:21.1.7-3+deb12u10)
bullseye: resolved (fixed in 2:1.20.11-1+deb11u16)
forky: resolved (fixed in 2:21.1.16-1.2
debian
CVE-2024-0408P4MEDIUMCVSS 5.5fixed in xorg-server 2:21.1.7-3+deb12u5 (bookworm)2024
CVE-2024-0408 [MEDIUM] CVE-2024-0408: xorg-server - A flaw was found in the X.Org server. The GLX PBuffer code does not call the XAC...
A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another resource that needs to access that buffer, such as a GC, the XSELINUX code will try to use an object that was never
debian
CVE-2025-49178P4MEDIUMCVSS 5.5fixed in xorg-server 2:21.1.7-3+deb12u10 (bookworm)2025
CVE-2025-49178 [MEDIUM] CVE-2025-49178: xorg-server - A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' ...
A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the server to skip processing another client's request, potentially leading to a denial of service.
Scope: local
bookworm: resolved (fixed in 2:21.1.7-3+deb12u10)
bullseye: resolved (fixed in 2:1.20.11-1+deb11u16)
forky: resolved (fixed in 2:21.1.16-
debian
← Previous3 / 3