Skip to content
Noroxi

X.Org records

168 published records for vendor x.org.

Researcher profile

Entered KEV
0 · 0%
Weaponized
2 · 1.2%
Pre-auth RCE
29
With a fix record
96.4%
Median publish → KEV
No record has entered KEV

All records

168 records
  • An X server's access control is disabled (e.g.

    CriticalCVSS 10.0WeaponizedEPSS 21%

    x.org · x11Jul 1, 1997

  • Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2)

    CriticalCVSS 10.0No exploitEPSS 9%

    lesstif · lesstifJan 10, 2005

  • LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code.

    CriticalCVSS 9.8No exploitEPSS 11%

    x.org · libx11May 27, 2021

  • An issue was discovered in libX11 through 1.6.5.

    CriticalCVSS 9.8No exploitEPSS 9%

    x.org · libx11Aug 24, 2018

  • Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attack

    CriticalCVSS 9.8No exploitEPSS 8%

    x.org · libxpmFeb 1, 2017

  • Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allow

    CriticalCVSS 10.0No exploitEPSS 3%

    x.org · x.orgDec 31, 2006

  • Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service o

    CriticalCVSS 10.0No exploitEPSS 3%

    x.org · x11May 18, 2012

  • An issue was discovered in libX11 through 1.6.5.

    CriticalCVSS 9.8No exploitEPSS 5%

    x.org · libx11Aug 24, 2018

  • The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memo

    CriticalCVSS 9.8No exploitEPSS 5%

    x.org · libxvDec 13, 2016

  • xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X ser

    CriticalCVSS 9.8No exploitEPSS 4%

    debian · debian linuxJan 24, 2018

  • xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to

    CriticalCVSS 9.8No exploitEPSS 4%

    debian · debian linuxJan 24, 2018

  • xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash o

    CriticalCVSS 9.8No exploitEPSS 4%

    debian · debian linuxJan 24, 2018

  • The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geo

    CriticalCVSS 9.8No exploitEPSS 4%

    x.org · libx11Dec 13, 2016

  • The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, wh

    CriticalCVSS 9.8No exploitEPSS 4%

    x.org · libx11Dec 13, 2016

  • xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or po

    CriticalCVSS 9.8No exploitEPSS 4%

    debian · debian linuxJan 24, 2018

  • xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash

    CriticalCVSS 9.8No exploitEPSS 4%

    debian · debian linuxJan 24, 2018

  • xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to cra

    CriticalCVSS 9.8No exploitEPSS 4%

    debian · debian linuxJan 24, 2018

  • xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash

    CriticalCVSS 9.8No exploitEPSS 4%

    debian · debian linuxJan 24, 2018

  • xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to c

    CriticalCVSS 9.8No exploitEPSS 4%

    debian · debian linuxJan 24, 2018

  • xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or

    CriticalCVSS 9.8No exploitEPSS 4%

    debian · debian linuxJan 24, 2018

  • xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X

    CriticalCVSS 9.8No exploitEPSS 4%

    debian · debian linuxJan 24, 2018

  • xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server t

    CriticalCVSS 9.8No exploitEPSS 4%

    debian · debian linuxJan 24, 2018

  • Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X ser

    CriticalCVSS 9.8No exploitEPSS 4%

    x.org · libxrenderDec 13, 2016

  • X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.

    CriticalCVSS 9.8No exploitEPSS 4%

    x.org · libxrandrDec 13, 2016

  • Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted re

    CriticalCVSS 9.8No exploitEPSS 4%

    x.org · libxrandrDec 13, 2016