X.Org X Server vulnerabilities

80 known vulnerabilities affecting x.org/x_server.

Total CVEs
80
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL14HIGH42MEDIUM21LOW3

Vulnerabilities

Page 2 of 4
CVE-2022-4283HIGHCVSS 7.8v1.20.42022-12-14
CVE-2022-4283 [HIGH] CWE-416 CVE-2022-4283: A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh
nvd
CVE-2022-46344HIGHCVSS 8.8v1.20.42022-12-14
CVE-2022-46344 [HIGH] CWE-125 CVE-2022-46344: A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangePr A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclosure. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution
nvd
CVE-2022-46342HIGHCVSS 8.8v1.20.42022-12-14
CVE-2022-46342 [HIGH] CWE-416 CVE-2022-46342: A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelect A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se
nvd
CVE-2022-46341HIGHCVSS 8.8v1.20.42022-12-14
CVE-2022-46341 [HIGH] CWE-787 CVE-2022-46341: A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveU A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveUngrab request accesses out-of-bounds memory when invoked with a high keycode or button code. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
nvd
CVE-2022-46343HIGHCVSS 8.8v1.20.42022-12-14
CVE-2022-46343 [HIGH] CWE-416 CVE-2022-46343: A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSave A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
nvd
CVE-2022-46340HIGHCVSS 8.8v1.20.42022-12-14
CVE-2022-46340 [HIGH] CWE-787 CVE-2022-46340: A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTest A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of the XTest extension may corrupt the stack if GenericEvents with lengths larger than 32 bytes are sent through a the XTestFakeInput request. This issue can lead to local privileges elevation on systems where the X server is running p
nvd
CVE-2022-3550HIGHCVSS 8.8fixed in 21.1.62022-10-17
CVE-2022-3550 [MEDIUM] CWE-119 CVE-2022-3550: A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.
nvd
CVE-2022-3551MEDIUMCVSS 6.5fixed in 21.1.62022-10-17
CVE-2022-3551 [LOW] CWE-404 CVE-2022-3551: A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by th A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by this issue is the function ProcXkbGetKbdByName of the file xkb/xkb.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211052.
nvd
CVE-2022-2319HIGHCVSS 7.8v21.1.02022-09-01
CVE-2022-2319 [HIGH] CWE-1320 CVE-2022-2319: A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur in the ProcXkbSetGe A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur in the ProcXkbSetGeometry function due to improper validation of the request length.
nvd
CVE-2022-2320HIGHCVSS 7.8v21.1.02022-09-01
CVE-2022-2320 [HIGH] CWE-787 CVE-2022-2320: A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetD A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the
nvd
CVE-2021-4011HIGHCVSS 7.8fixed in 1.20.14v21.1.0+1 more2021-12-17
CVE-2021-4011 [HIGH] CWE-119 CVE-2021-4011: A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds a A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2021-4008HIGHCVSS 7.8fixed in 1.20.14v21.1.0+1 more2021-12-17
CVE-2021-4008 [HIGH] CWE-119 CVE-2021-4008: A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds a A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2021-4009HIGHCVSS 7.8fixed in 1.20.14v21.1.0+1 more2021-12-17
CVE-2021-4009 [HIGH] CWE-119 CVE-2021-4009: A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds a A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcXFixesCreatePointerBarrier function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2021-4010HIGHCVSS 7.8fixed in 1.20.14v21.1.0+1 more2021-12-17
CVE-2021-4010 [HIGH] CWE-119 CVE-2021-4010: A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds a A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSuspend function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2021-3472HIGHCVSS 7.8fixed in 1.20.112021-04-26
CVE-2021-3472 [HIGH] CWE-191 CVE-2021-3472: A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xs A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead to a local privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2020-14360HIGHCVSS 7.8fixed in 1.20.102021-01-20
CVE-2020-14360 [HIGH] CWE-119 CVE-2020-14360: A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMa A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2020-25712HIGHCVSS 7.8fixed in 1.20.102020-12-15
CVE-2020-25712 [HIGH] CWE-122 CVE-2020-25712: A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may l A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2020-14362HIGHCVSS 7.8fixed in 1.20.92020-09-15
CVE-2020-14362 [HIGH] CWE-191 CVE-2020-14362: A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2020-14361HIGHCVSS 7.8fixed in 1.20.92020-09-15
CVE-2020-14361 [HIGH] CWE-191 CVE-2020-14361: A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2020-14346HIGHCVSS 7.8fixed in 1.20.92020-09-15
CVE-2020-14346 [HIGH] CWE-191 CVE-2020-14346: A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension pro A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd