CVE-2022-2320 |
AVG-2770 |
High |
No |
Privilege escalation |
The handler for the ProcXkbSetGeometry request of the Xkb extension does not properly validate the request length leading to out of bounds memory write. |
CVE-2022-2319 |
AVG-2770 |
High |
No |
Privilege escalation |
The handler for the ProcXkbSetDeviceInfo request of the Xkb extension does not properly validate the request length leading to out of bounds memory write. |
CVE-2021-4011 |
AVG-2636 |
High |
Yes |
Arbitrary code execution |
A security issue has been found in X.Org before version 21.1.2 and Xwayland before version 21.1.4. The handlers for the RecordCreateContext and... |
CVE-2021-4010 |
AVG-2636 |
High |
Yes |
Arbitrary code execution |
A security issue has been found in X.Org before version 21.1.2 and Xwayland before version 21.1.4. The handler for the Suspend request of the Screen Saver... |
CVE-2021-4009 |
AVG-2636 |
High |
Yes |
Arbitrary code execution |
A security issue has been found in X.Org before version 21.1.2 and Xwayland before version 21.1.4. The handler for the CreatePointerBarrier request of the... |
CVE-2021-4008 |
AVG-2636 |
High |
Yes |
Arbitrary code execution |
A security issue has been found in X.Org before version 21.1.2 and Xwayland before version 21.1.4. The handler for the CompositeGlyphs request of the Render... |
CVE-2021-3472 |
AVG-1811 |
Medium |
No |
Privilege escalation |
A security issue has been found in xorg-server before version 1.20.11 and xorg-xwayland before version 21.1.1. Insufficient checks on the lengths of the... |
CVE-2020-25712 |
AVG-1310 |
Medium |
No |
Arbitrary code execution |
A security issue was discovered in xorg-server before 1.20.10. Insufficient checks on input of the XkbSetDeviceInfo request can lead to a buffer overflow on... |
CVE-2020-14360 |
AVG-1310 |
Medium |
No |
Arbitrary code execution |
A security issue was discovered in xorg-server before 1.20.10. Insufficient checks on the lengths of the XkbSetMap request can lead to out of bounds memory... |
CVE-2020-14347 |
AVG-1211 |
Low |
No |
Information disclosure |
Allocation for pixmap data in AllocatePixmap() does not initialize the memory in xserver, it leads to leak uninitialize heap memory to clients. When the X... |
CVE-2018-14665 |
AVG-788 |
High |
Yes |
Privilege escalation |
Incorrect command-line parameter validation in the Xorg X server can lead to privilege elevation and/or arbitrary files overwrite, when the X server is... |
CVE-2017-13723 |
AVG-432 |
Medium |
No |
Arbitrary code execution |
A stack buffer overflow was found in xkbtext.c, which didn't handle xkb formatted string output safely due to a single shared static buffer. The fix... |
CVE-2017-13721 |
AVG-432 |
Low |
No |
Denial of service |
A denial of service vulnerability was found in xorg-server in the ProcShmCreateSegment function due to a missing shmseg resource ids validation. A passed... |
CVE-2017-12183 |
AVG-443 |
High |
Yes |
Arbitrary code execution |
A security issue has been found in the xfixes component of xorg- server, where buffer lengths were not correctly validated. |
CVE-2017-12178 |
AVG-443 |
High |
Yes |
Arbitrary code execution |
A security issue has been found in the Xi component of xorg-server, due to an invalid length check in ProcXIChangeHierarchy. |
CVE-2017-12177 |
AVG-443 |
High |
Yes |
Arbitrary code execution |
A security issue has been found in the double buffer extension component of xorg-server, due to a missing validation of the length of a variable-length... |
CVE-2017-12176 |
AVG-443 |
High |
Yes |
Arbitrary code execution |
A security issue has been found in xorg-server, due to a missing validation of the extra length in ProcEstablishConnection(). |
CVE-2017-10972 |
AVG-341 |
High |
Yes |
Information disclosure |
Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server on v1.19.3 and before allowed authenticated malicious users to... |
CVE-2017-10971 |
AVG-341 |
High |
Yes |
Arbitrary code execution |
In the X.Org X server on v.1.19.3, a user authenticated to an X Session could crash or execute code in the context of the X Server by exploiting a stack... |