X.Org X11 vulnerabilities
18 known vulnerabilities affecting x.org/x11.
Total CVEs
18
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH1MEDIUM14
Vulnerabilities
Page 1 of 1
CVE-2013-7439HIGHCVSS 7.5v6.0v6.1+9 more2015-04-16
CVE-2013-7439 [HIGH] CWE-189 CVE-2013-7439: Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h i
Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 before 1.6.0 allow remote attackers to have unspecified impact via a crafted request, which triggers a buffer overflow.
nvd
CVE-2014-8092MEDIUMCVSS 6.5v1.02014-12-10
CVE-2014-8092 [MEDIUM] CVE-2014-8092: Multiple integer overflows in X.Org X Window System (aka X11 or X) X11R1 and X.Org Server (aka xserv
Multiple integer overflows in X.Org X Window System (aka X11 or X) X11R1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to the (1) ProcPutImage, (2) GetHosts, (3) RegionSizeof, or (4) REQUEST_FIXED_SIZE function, which t
nvd
CVE-2014-8097MEDIUMCVSS 6.5v6.12014-12-10
CVE-2014-8097 [MEDIUM] CWE-119 CVE-2014-8097: The DBE extension in X.Org X Window System (aka X11 or X) X11R6.1 and X.Org Server (aka xserver and
The DBE extension in X.Org X Window System (aka X11 or X) X11R6.1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) ProcDbeSwapBuffers or (2) SProcDbeSwapBuffers functi
nvd
CVE-2014-8099MEDIUMCVSS 6.5v6.72014-12-10
CVE-2014-8099 [MEDIUM] CWE-119 CVE-2014-8099: The XVideo extension in XFree86 4.0.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Serve
The XVideo extension in XFree86 4.0.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) SProcXvQueryExtension, (2) SProc
nvd
CVE-2014-8091MEDIUMCVSS 4.3v5.02014-12-10
CVE-2014-8091 [MEDIUM] CVE-2014-8091: X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver and xorg-server) before 1.
X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver and xorg-server) before 1.16.3, when using SUN-DES-1 (Secure RPC) authentication credentials, does not check the return value of a malloc call, which allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a crafted connection request.
nvd
CVE-2014-8101MEDIUMCVSS 6.5v6.72014-12-10
CVE-2014-8101 [MEDIUM] CWE-119 CVE-2014-8101: The RandR extension in XFree86 4.2.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server
The RandR extension in XFree86 4.2.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) SProcRRQueryVersion, (2) SProcRRG
nvd
CVE-2014-8093MEDIUMCVSS 6.5v6.72014-12-10
CVE-2014-8093 [MEDIUM] CVE-2014-8093: Multiple integer overflows in the GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X)
Multiple integer overflows in the GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to the (1) __glXDisp_ReadPixels, (2) __glXDispSwap_ReadPixels,
nvd
CVE-2014-8098MEDIUMCVSS 6.5v6.72014-12-10
CVE-2014-8098 [MEDIUM] CWE-119 CVE-2014-8098: The GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (ak
The GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) __glXDisp_Render, (2) __glXDisp_Rende
nvd
CVE-2014-8095MEDIUMCVSS 6.5v4.02014-12-10
CVE-2014-8095 [MEDIUM] CWE-119 CVE-2014-8095: The XInput extension in X.Org X Window System (aka X11 or X) X11R4 and X.Org Server (aka xserver and
The XInput extension in X.Org X Window System (aka X11 or X) X11R4 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) SProcXChangeDeviceControl, (2) ProcXChangeDeviceCo
nvd
CVE-2014-8096MEDIUMCVSS 6.5v6.02014-12-10
CVE-2014-8096 [MEDIUM] CWE-119 CVE-2014-8096: The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X)
The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X) X11R6.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value.
nvd
CVE-2014-8102MEDIUMCVSS 6.5v6.82014-12-10
CVE-2014-8102 [MEDIUM] CWE-119 CVE-2014-8102: The SProcXFixesSelectSelectionInput function in the XFixes extension in X.Org X Window System (aka X
The SProcXFixesSelectSelectionInput function in the XFixes extension in X.Org X Window System (aka X11 or X) X11R6.8.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length value.
nvd
CVE-2014-8100MEDIUMCVSS 6.5v6.72014-12-10
CVE-2014-8100 [MEDIUM] CWE-119 CVE-2014-8100: The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Serve
The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) ProcRenderQueryVersion, (2) SPro
nvd
CVE-2012-2118CRITICALCVSS 10.0v1.112012-05-18
CVE-2012-2118 [CRITICAL] CWE-20 CVE-2012-2118: Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows
Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in an input device name.
nvd
CVE-2009-3100MEDIUMCVSS 4.0v6.4.12009-09-08
CVE-2009-3100 [MEDIUM] CVE-2009-3100: xscreensaver (aka Gnome-XScreenSaver) in Sun Solaris 9 and 10, OpenSolaris snv_109 through snv_122,
xscreensaver (aka Gnome-XScreenSaver) in Sun Solaris 9 and 10, OpenSolaris snv_109 through snv_122, and X11 6.4.1 on Solaris 8 does not properly handle Accessibility support, which allows local users to cause a denial of service (system hang) by locking the screen and then attempting to launch an Accessibility pop-up window, related to a regression in certain
nvd
CVE-2009-2711MEDIUMCVSS 4.9v6.4.12009-08-07
CVE-2009-2711 [MEDIUM] CVE-2009-2711: XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when
XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when the Xorg or Xnewt server is used, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276.
nvd
CVE-2007-1003CRITICALCVSS 9.0v7.1_1.1.02007-04-06
CVE-2007-1003 [CRITICAL] CVE-2007-1003: Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in
Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, allows remote authenticated users to execute arbitrary code via a large expression, which results in memory corruption.
nvd
CVE-1999-0965MEDIUMCVSS 6.2fixed in 5.0v5.01997-09-19
CVE-1999-0965 [MEDIUM] CVE-1999-0965: Race condition in xterm allows local users to modify arbitrary files via the logging option.
Race condition in xterm allows local users to modify arbitrary files via the logging option.
nvd
CVE-1999-0526CRITICALCVSS 10.0v7.1_1.1.01997-07-01
CVE-1999-0526 [CRITICAL] CVE-1999-0526: An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to co
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
nvd