X.Org records
168 published records for vendor x.org.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 1.2%
- Pre-auth RCE
- 29
- With a fix record
- 96.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer29
- CWE-787 Out-of-bounds Write17
- CWE-416 Use After Free16
- CWE-391 Unchecked Error Condition12
- CWE-125 Out-of-bounds Read8
- CWE-190 Integer Overflow or Wraparound7
The weakness classes this vendor ships most often: where to look.
CWEAll records
168 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-1999-0526Weaponized | An X server's access control is disabled (e.g.x.org · x11 | Critical10.0 | — | 20.8% | Jul 1, 1997 |
43Plan | CVE-2004-0914No exploit | Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2)lesstif · lesstif | Critical10.0 | — | 8.7% | Jan 10, 2005 |
42Plan | CVE-2021-31535No exploit | LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code.x.org · libx11 · CWE-120 | Critical9.8 | — | 10.6% | May 27, 2021 |
42Plan | CVE-2018-14600No exploit | An issue was discovered in libX11 through 1.6.5.x.org · libx11 · CWE-787 | Critical9.8 | — | 9.3% | Aug 24, 2018 |
41Plan | CVE-2016-10164No exploit | Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackx.org · libxpm · CWE-119 | Critical9.8 | — | 7.6% | Feb 1, 2017 |
41Plan | CVE-2006-6102No exploit | Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allowx.org · x.org | Critical10.0 | — | 3.4% | Dec 31, 2006 |
41Plan | CVE-2012-2118No exploit | Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service ox.org · x11 · CWE-20 | Critical10.0 | — | 2.7% | May 18, 2012 |
40Plan | CVE-2018-14599No exploit | An issue was discovered in libX11 through 1.6.5.x.org · libx11 · CWE-193 | Critical9.8 | — | 4.8% | Aug 24, 2018 |
40Plan | CVE-2016-5407No exploit | The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memox.org · libxv · CWE-119 | Critical9.8 | — | 4.5% | Dec 13, 2016 |
40Plan | CVE-2017-12177No exploit | xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X serdebian · debian linux · CWE-391 | Critical9.8 | — | 4.4% | Jan 24, 2018 |
40Plan | CVE-2017-12179No exploit | xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to debian · debian linux · CWE-391 | Critical9.8 | — | 4.4% | Jan 24, 2018 |
40Plan | CVE-2017-12186No exploit | xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash odebian · debian linux · CWE-391 | Critical9.8 | — | 4.3% | Jan 24, 2018 |
40Plan | CVE-2016-7942No exploit | The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geox.org · libx11 · CWE-264 | Critical9.8 | — | 4.3% | Dec 13, 2016 |
40Plan | CVE-2016-7943No exploit | The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, whx.org · libx11 · CWE-787 | Critical9.8 | — | 4.3% | Dec 13, 2016 |
40Plan | CVE-2017-12183No exploit | xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or podebian · debian linux · CWE-391 | Critical9.8 | — | 4.2% | Jan 24, 2018 |
40Plan | CVE-2017-12182No exploit | xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash debian · debian linux · CWE-391 | Critical9.8 | — | 4.2% | Jan 24, 2018 |
40Plan | CVE-2017-12180No exploit | xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to cradebian · debian linux · CWE-391 | Critical9.8 | — | 4.2% | Jan 24, 2018 |
40Plan | CVE-2017-12181No exploit | xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash debian · debian linux · CWE-391 | Critical9.8 | — | 4.2% | Jan 24, 2018 |
40Plan | CVE-2017-12185No exploit | xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to cdebian · debian linux · CWE-391 | Critical9.8 | — | 4.2% | Jan 24, 2018 |
40Plan | CVE-2017-12184No exploit | xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or debian · debian linux · CWE-391 | Critical9.8 | — | 4.2% | Jan 24, 2018 |
40Plan | CVE-2017-12176No exploit | xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause Xdebian · debian linux · CWE-391 | Critical9.8 | — | 4.2% | Jan 24, 2018 |
40Plan | CVE-2017-12178No exploit | xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server tdebian · debian linux · CWE-391 | Critical9.8 | — | 4.2% | Jan 24, 2018 |
40Plan | CVE-2016-7949No exploit | Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X serx.org · libxrender · CWE-20 | Critical9.8 | — | 3.7% | Dec 13, 2016 |
40Plan | CVE-2016-7948No exploit | X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.x.org · libxrandr · CWE-787 | Critical9.8 | — | 3.6% | Dec 13, 2016 |
40Plan | CVE-2016-7947No exploit | Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted rex.org · libxrandr · CWE-190 | Critical9.8 | — | 3.6% | Dec 13, 2016 |
- CVE-1999-052646Plan
An X server's access control is disabled (e.g.
CriticalCVSS 10.0WeaponizedEPSS 21%x.org · x11Jul 1, 1997
- CVE-2004-091443Plan
Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2)
CriticalCVSS 10.0No exploitEPSS 9%lesstif · lesstifJan 10, 2005
- CVE-2021-3153542Plan
LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code.
CriticalCVSS 9.8No exploitEPSS 11%x.org · libx11May 27, 2021
- CVE-2018-1460042Plan
An issue was discovered in libX11 through 1.6.5.
CriticalCVSS 9.8No exploitEPSS 9%x.org · libx11Aug 24, 2018
- CVE-2016-1016441Plan
Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attack
CriticalCVSS 9.8No exploitEPSS 8%x.org · libxpmFeb 1, 2017
- CVE-2006-610241Plan
Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allow
CriticalCVSS 10.0No exploitEPSS 3%x.org · x.orgDec 31, 2006
- CVE-2012-211841Plan
Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service o
CriticalCVSS 10.0No exploitEPSS 3%x.org · x11May 18, 2012
- CVE-2018-1459940Plan
An issue was discovered in libX11 through 1.6.5.
CriticalCVSS 9.8No exploitEPSS 5%x.org · libx11Aug 24, 2018
- CVE-2016-540740Plan
The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memo
CriticalCVSS 9.8No exploitEPSS 5%x.org · libxvDec 13, 2016
- CVE-2017-1217740Plan
xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X ser
CriticalCVSS 9.8No exploitEPSS 4%debian · debian linuxJan 24, 2018
- CVE-2017-1217940Plan
xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to
CriticalCVSS 9.8No exploitEPSS 4%debian · debian linuxJan 24, 2018
- CVE-2017-1218640Plan
xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash o
CriticalCVSS 9.8No exploitEPSS 4%debian · debian linuxJan 24, 2018
- CVE-2016-794240Plan
The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geo
CriticalCVSS 9.8No exploitEPSS 4%x.org · libx11Dec 13, 2016
- CVE-2016-794340Plan
The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, wh
CriticalCVSS 9.8No exploitEPSS 4%x.org · libx11Dec 13, 2016
- CVE-2017-1218340Plan
xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or po
CriticalCVSS 9.8No exploitEPSS 4%debian · debian linuxJan 24, 2018
- CVE-2017-1218240Plan
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash
CriticalCVSS 9.8No exploitEPSS 4%debian · debian linuxJan 24, 2018
- CVE-2017-1218040Plan
xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to cra
CriticalCVSS 9.8No exploitEPSS 4%debian · debian linuxJan 24, 2018
- CVE-2017-1218140Plan
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash
CriticalCVSS 9.8No exploitEPSS 4%debian · debian linuxJan 24, 2018
- CVE-2017-1218540Plan
xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to c
CriticalCVSS 9.8No exploitEPSS 4%debian · debian linuxJan 24, 2018
- CVE-2017-1218440Plan
xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or
CriticalCVSS 9.8No exploitEPSS 4%debian · debian linuxJan 24, 2018
- CVE-2017-1217640Plan
xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X
CriticalCVSS 9.8No exploitEPSS 4%debian · debian linuxJan 24, 2018
- CVE-2017-1217840Plan
xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server t
CriticalCVSS 9.8No exploitEPSS 4%debian · debian linuxJan 24, 2018
- CVE-2016-794940Plan
Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X ser
CriticalCVSS 9.8No exploitEPSS 4%x.org · libxrenderDec 13, 2016
- CVE-2016-794840Plan
X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.
CriticalCVSS 9.8No exploitEPSS 4%x.org · libxrandrDec 13, 2016
- CVE-2016-794740Plan
Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted re
CriticalCVSS 9.8No exploitEPSS 4%x.org · libxrandrDec 13, 2016