X.Org Xorg-Server vulnerabilities
124 known vulnerabilities affecting x.org/xorg-server.
Total CVEs
124
CISA KEV
0
Public exploits
5
Exploited in wild
2
Severity breakdown
CRITICAL21HIGH58MEDIUM38LOW7
Vulnerabilities
Page 6 of 7
CVE-2017-2624P4HIGHCVSS 7.0≥ 0, < 2:1.19.2-12018-07-27
CVE-2017-2624 [HIGH] CVE-2017-2624: It was found that xorg-x11-server before 1
It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.
osv
CVE-2020-14347P4MEDIUMCVSS 5.5≥ 0, < 2:1.20.9-12020-08-05
CVE-2020-14347 [MEDIUM] CVE-2020-14347: A flaw was found in the way xserver memory was not properly initialized
A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.
osv
CVE-2006-4447P4HIGHCVSS 7.2v1.02_r52006-08-30
CVE-2006-4447 [HIGH] CVE-2006-4447: X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check t
X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit.
nvdosv
CVE-2025-49175P4MEDIUMCVSS 6.1≥ 0, < 2:1.20.11-1+deb11u16≥ 0, < 2:21.1.7-3+deb12u10+1 more2025-06-17
CVE-2025-49175 [MEDIUM] CVE-2025-49175: A flaw was found in the X Rendering extension's handling of animated cursors
A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the server assumes at least one is present, leading to an out-of-bounds read and potential crash.
osv
CVE-2006-6101P4MEDIUMCVSS 6.6≥ 0, < 2:1.1.1-152006-12-31
CVE-2006-6101 [MEDIUM] CVE-2006-6101: Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X
Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of glyph management data structures.
osv
CVE-2014-8091P4MEDIUMCVSS 4.3≥ 0, < 2:1.16.2.901-12014-12-10
CVE-2014-8091 [MEDIUM] CVE-2014-8091: X
X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver and xorg-server) before 1.16.3, when using SUN-DES-1 (Secure RPC) authentication credentials, does not check the return value of a malloc call, which allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a crafted connection request.
osv
CVE-2024-0408P4MEDIUMCVSS 5.5≥ 0, < 2:1.20.11-1+deb11u11≥ 0, < 2:21.1.7-3+deb12u5+1 more2024-01-18
CVE-2024-0408 [MEDIUM] CVE-2024-0408: A flaw was found in the X
A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another resource that needs to access that buffer, such as a GC, the XSELINUX code will try to use an object that was never labeled and crash because the SID is NULL.
osv
CVE-2008-2361P4MEDIUMCVSS 6.8≥ 0, < 2:1.4.1~git20080517-22008-06-16
CVE-2008-2361 [MEDIUM] CVE-2008-2361: Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1
Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size, which triggers a dereference of unmapped memory.
osv
CVE-2006-6103P4MEDIUMCVSS 6.6≥ 0, < 2:1.1.1-152006-12-31
CVE-2006-6103 [MEDIUM] CVE-2006-6103: Integer overflow in the ProcDbeSwapBuffers function in the DBE extension for X
Integer overflow in the ProcDbeSwapBuffers function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of unspecified data structures.
osv
CVE-2007-6428P4MEDIUMCVSS 5.0≥ 0, < 2:1.4.1~git20080105-22008-01-18
CVE-2007-6428 [MEDIUM] CVE-2007-6428: The ProcGetReservedColormapEntries function in the TOG-CUP extension in X
The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request containing a 32-bit value that is improperly used as an array index.
osv
CVE-2025-49178P4MEDIUMCVSS 5.5≥ 0, < 2:1.20.11-1+deb11u16≥ 0, < 2:21.1.7-3+deb12u10+1 more2025-06-17
CVE-2025-49178 [MEDIUM] CVE-2025-49178: A flaw was found in the X server's request handling
A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the server to skip processing another client's request, potentially leading to a denial of service.
osv
CVE-2013-6424P4MEDIUMCVSS 5.0≥ 0, < 2:1.14.2.901-12014-01-18
CVE-2013-6424 [MEDIUM] CVE-2013-6424: Integer underflow in the xTrapezoidValid macro in render/picture
Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
osv
CVE-2023-5380P4MEDIUMCVSS 4.7≥ 0, < 2:1.20.11-1+deb11u8≥ 0, < 2:21.1.7-3+deb12u2+1 more2023-10-25
CVE-2023-5380 [MEDIUM] CVE-2023-5380: A use-after-free flaw was found in the xorg-x11-server
A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.
osv
CVE-2007-4730P4MEDIUMCVSS 4.3v1.01v1.1+3 more2007-09-11
CVE-2007-4730 [MEDIUM] CWE-119 CVE-2007-4730: Buffer overflow in the compNewPixmap function in compalloc.c in the Composite extension for the X.or
Buffer overflow in the compNewPixmap function in compalloc.c in the Composite extension for the X.org X11 server before 1.4 allows local users to execute arbitrary code by copying data from a large pixel depth pixmap into a smaller pixel depth pixmap.
nvdosv
CVE-2012-0064P4MEDIUMCVSS 4.6≥ 0, < 2:1.11.3.901-22014-02-10
CVE-2012-0064 [MEDIUM] CVE-2012-0064: xkeyboard-config before 2
xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physically proximate attackers to bypass an X screen lock via keyboard combinations that break the input grab.
osv
CVE-2017-13721P4MEDIUMCVSS 4.7≥ 0, < 2:1.19.4-12017-10-10
CVE-2017-13721 [MEDIUM] CVE-2017-13721: In X
In X.Org Server (aka xserver and xorg-server) before 1.19.4, an attacker authenticated to an X server with the X shared memory extension enabled can cause aborts of the X server or replace shared memory segments of other X clients in the same session.
osv
CVE-2009-1573P4MEDIUMCVSS 4.6≥ 0, < 2:1.6.1.901-32009-05-06
CVE-2009-1573 [MEDIUM] CVE-2009-1573: xvfb-run 1
xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.
osv
CVE-2007-3920P4MEDIUMCVSS 4.6≥ 0, < 2:1.4.1~git20080118-12007-10-29
CVE-2007-3920 [MEDIUM] CVE-2007-3920: GNOME screensaver 2
GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069.
osv
CVE-2015-3164P4LOWCVSS 3.6v1.16.4v1.16.99.901+2 more2015-07-01
CVE-2015-3164 [LOW] CWE-264 CVE-2015-3164: The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authen
The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.
nvdosv
CVE-2010-4819P4LOWCVSS 3.6≥ 0, < 2:1.9.0.901-12012-09-05
CVE-2010-4819 [LOW] CVE-2010-4819: The ProcRenderAddGlyphs function in the Render extension (render/render
The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."
osv