Записи X.Org
168 опубликованных записей вендора x.org.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 1,2 %
- Pre-auth RCE
- 29
- С записью об исправлении
- 96,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer29
- CWE-787 Out-of-bounds Write17
- CWE-416 Use After Free16
- CWE-391 Unchecked Error Condition12
- CWE-125 Out-of-bounds Read8
- CWE-190 Integer Overflow or Wraparound7
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
168 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
46В плане | CVE-1999-0526Готовый эксплойт | An X server's access control is disabled (e.g.x.org · x11 | Критическая10,0 | — | 20,8 % | 1 июл. 1997 г. |
43В плане | CVE-2004-0914Эксплойта нет | Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2)lesstif · lesstif | Критическая10,0 | — | 8,7 % | 10 янв. 2005 г. |
42В плане | CVE-2021-31535Эксплойта нет | LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code.x.org · libx11 · CWE-120 | Критическая9,8 | — | 10,6 % | 27 мая 2021 г. |
42В плане | CVE-2018-14600Эксплойта нет | An issue was discovered in libX11 through 1.6.5.x.org · libx11 · CWE-787 | Критическая9,8 | — | 9,3 % | 24 авг. 2018 г. |
41В плане | CVE-2016-10164Эксплойта нет | Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackx.org · libxpm · CWE-119 | Критическая9,8 | — | 7,6 % | 1 февр. 2017 г. |
41В плане | CVE-2006-6102Эксплойта нет | Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allowx.org · x.org | Критическая10,0 | — | 3,5 % | 31 дек. 2006 г. |
41В плане | CVE-2012-2118Эксплойта нет | Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service ox.org · x11 · CWE-20 | Критическая10,0 | — | 2,7 % | 18 мая 2012 г. |
40В плане | CVE-2018-14599Эксплойта нет | An issue was discovered in libX11 through 1.6.5.x.org · libx11 · CWE-193 | Критическая9,8 | — | 4,8 % | 24 авг. 2018 г. |
40В плане | CVE-2016-5407Эксплойта нет | The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memox.org · libxv · CWE-119 | Критическая9,8 | — | 4,5 % | 13 дек. 2016 г. |
40В плане | CVE-2017-12183Эксплойта нет | xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or podebian · debian linux · CWE-391 | Критическая9,8 | — | 4,5 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12180Эксплойта нет | xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to cradebian · debian linux · CWE-391 | Критическая9,8 | — | 4,5 % | 24 янв. 2018 г. |
40В плане | CVE-2016-7942Эксплойта нет | The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geox.org · libx11 · CWE-264 | Критическая9,8 | — | 4,5 % | 13 дек. 2016 г. |
40В плане | CVE-2016-7943Эксплойта нет | The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, whx.org · libx11 · CWE-787 | Критическая9,8 | — | 4,5 % | 13 дек. 2016 г. |
40В плане | CVE-2017-12178Эксплойта нет | xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server tdebian · debian linux · CWE-391 | Критическая9,8 | — | 4,4 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12177Эксплойта нет | xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X serdebian · debian linux · CWE-391 | Критическая9,8 | — | 4,4 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12179Эксплойта нет | xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to debian · debian linux · CWE-391 | Критическая9,8 | — | 4,4 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12186Эксплойта нет | xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash odebian · debian linux · CWE-391 | Критическая9,8 | — | 4,3 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12182Эксплойта нет | xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash debian · debian linux · CWE-391 | Критическая9,8 | — | 4,2 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12181Эксплойта нет | xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash debian · debian linux · CWE-391 | Критическая9,8 | — | 4,2 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12184Эксплойта нет | xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or debian · debian linux · CWE-391 | Критическая9,8 | — | 4,2 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12185Эксплойта нет | xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to cdebian · debian linux · CWE-391 | Критическая9,8 | — | 4,2 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12176Эксплойта нет | xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause Xdebian · debian linux · CWE-391 | Критическая9,8 | — | 4,2 % | 24 янв. 2018 г. |
40В плане | CVE-2016-7949Эксплойта нет | Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X serx.org · libxrender · CWE-20 | Критическая9,8 | — | 3,7 % | 13 дек. 2016 г. |
40В плане | CVE-2016-7948Эксплойта нет | X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.x.org · libxrandr · CWE-787 | Критическая9,8 | — | 3,6 % | 13 дек. 2016 г. |
40В плане | CVE-2016-7947Эксплойта нет | Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted rex.org · libxrandr · CWE-190 | Критическая9,8 | — | 3,6 % | 13 дек. 2016 г. |
- CVE-1999-052646В плане
An X server's access control is disabled (e.g.
КритическаяCVSS 10,0Готовый эксплойтEPSS 21 %x.org · x111 июл. 1997 г.
- CVE-2004-091443В плане
Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2)
КритическаяCVSS 10,0Эксплойта нетEPSS 9 %lesstif · lesstif10 янв. 2005 г.
- CVE-2021-3153542В плане
LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code.
КритическаяCVSS 9,8Эксплойта нетEPSS 11 %x.org · libx1127 мая 2021 г.
- CVE-2018-1460042В плане
An issue was discovered in libX11 through 1.6.5.
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %x.org · libx1124 авг. 2018 г.
- CVE-2016-1016441В плане
Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attack
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %x.org · libxpm1 февр. 2017 г.
- CVE-2006-610241В плане
Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allow
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %x.org · x.org31 дек. 2006 г.
- CVE-2012-211841В плане
Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service o
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %x.org · x1118 мая 2012 г.
- CVE-2018-1459940В плане
An issue was discovered in libX11 through 1.6.5.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %x.org · libx1124 авг. 2018 г.
- CVE-2016-540740В плане
The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memo
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %x.org · libxv13 дек. 2016 г.
- CVE-2017-1218340В плане
xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or po
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1218040В плане
xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to cra
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2016-794240В плане
The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geo
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %x.org · libx1113 дек. 2016 г.
- CVE-2016-794340В плане
The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, wh
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %x.org · libx1113 дек. 2016 г.
- CVE-2017-1217840В плане
xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server t
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1217740В плане
xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X ser
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1217940В плане
xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1218640В плане
xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash o
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1218240В плане
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1218140В плане
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1218440В плане
xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1218540В плане
xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to c
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1217640В плане
xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2016-794940В плане
Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X ser
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %x.org · libxrender13 дек. 2016 г.
- CVE-2016-794840В плане
X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %x.org · libxrandr13 дек. 2016 г.
- CVE-2016-794740В плане
Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted re
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %x.org · libxrandr13 дек. 2016 г.