X.Org kayıtları
x.org üreticisine ait 168 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %1,2
- Pre-auth RCE
- 29
- Düzeltme kaydı olan
- %96,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer29
- CWE-787 Out-of-bounds Write17
- CWE-416 Use After Free16
- CWE-391 Unchecked Error Condition12
- CWE-125 Out-of-bounds Read8
- CWE-190 Integer Overflow or Wraparound7
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
168 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-1999-0526Silahlaştırılmış | An X server's access control is disabled (e.g.x.org · x11 | Kritik10,0 | — | %20,8 | 1 Tem 1997 |
43Planlayın | CVE-2004-0914İstismar yok | Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2)lesstif · lesstif | Kritik10,0 | — | %8,7 | 10 Oca 2005 |
42Planlayın | CVE-2021-31535İstismar yok | LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code.x.org · libx11 · CWE-120 | Kritik9,8 | — | %10,6 | 27 May 2021 |
42Planlayın | CVE-2018-14600İstismar yok | An issue was discovered in libX11 through 1.6.5.x.org · libx11 · CWE-787 | Kritik9,8 | — | %9,3 | 24 Ağu 2018 |
41Planlayın | CVE-2016-10164İstismar yok | Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackx.org · libxpm · CWE-119 | Kritik9,8 | — | %7,6 | 1 Şub 2017 |
41Planlayın | CVE-2006-6102İstismar yok | Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allowx.org · x.org | Kritik10,0 | — | %3,4 | 31 Ara 2006 |
41Planlayın | CVE-2012-2118İstismar yok | Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service ox.org · x11 · CWE-20 | Kritik10,0 | — | %2,7 | 18 May 2012 |
40Planlayın | CVE-2018-14599İstismar yok | An issue was discovered in libX11 through 1.6.5.x.org · libx11 · CWE-193 | Kritik9,8 | — | %4,8 | 24 Ağu 2018 |
40Planlayın | CVE-2016-5407İstismar yok | The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memox.org · libxv · CWE-119 | Kritik9,8 | — | %4,5 | 13 Ara 2016 |
40Planlayın | CVE-2017-12177İstismar yok | xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X serdebian · debian linux · CWE-391 | Kritik9,8 | — | %4,4 | 24 Oca 2018 |
40Planlayın | CVE-2017-12179İstismar yok | xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to debian · debian linux · CWE-391 | Kritik9,8 | — | %4,4 | 24 Oca 2018 |
40Planlayın | CVE-2017-12186İstismar yok | xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash odebian · debian linux · CWE-391 | Kritik9,8 | — | %4,3 | 24 Oca 2018 |
40Planlayın | CVE-2016-7942İstismar yok | The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geox.org · libx11 · CWE-264 | Kritik9,8 | — | %4,3 | 13 Ara 2016 |
40Planlayın | CVE-2016-7943İstismar yok | The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, whx.org · libx11 · CWE-787 | Kritik9,8 | — | %4,3 | 13 Ara 2016 |
40Planlayın | CVE-2017-12183İstismar yok | xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or podebian · debian linux · CWE-391 | Kritik9,8 | — | %4,2 | 24 Oca 2018 |
40Planlayın | CVE-2017-12182İstismar yok | xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash debian · debian linux · CWE-391 | Kritik9,8 | — | %4,2 | 24 Oca 2018 |
40Planlayın | CVE-2017-12180İstismar yok | xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to cradebian · debian linux · CWE-391 | Kritik9,8 | — | %4,2 | 24 Oca 2018 |
40Planlayın | CVE-2017-12181İstismar yok | xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash debian · debian linux · CWE-391 | Kritik9,8 | — | %4,2 | 24 Oca 2018 |
40Planlayın | CVE-2017-12185İstismar yok | xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to cdebian · debian linux · CWE-391 | Kritik9,8 | — | %4,2 | 24 Oca 2018 |
40Planlayın | CVE-2017-12184İstismar yok | xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or debian · debian linux · CWE-391 | Kritik9,8 | — | %4,2 | 24 Oca 2018 |
40Planlayın | CVE-2017-12176İstismar yok | xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause Xdebian · debian linux · CWE-391 | Kritik9,8 | — | %4,2 | 24 Oca 2018 |
40Planlayın | CVE-2017-12178İstismar yok | xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server tdebian · debian linux · CWE-391 | Kritik9,8 | — | %4,2 | 24 Oca 2018 |
40Planlayın | CVE-2016-7949İstismar yok | Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X serx.org · libxrender · CWE-20 | Kritik9,8 | — | %3,7 | 13 Ara 2016 |
40Planlayın | CVE-2016-7948İstismar yok | X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.x.org · libxrandr · CWE-787 | Kritik9,8 | — | %3,6 | 13 Ara 2016 |
40Planlayın | CVE-2016-7947İstismar yok | Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted rex.org · libxrandr · CWE-190 | Kritik9,8 | — | %3,6 | 13 Ara 2016 |
- CVE-1999-052646Planlayın
An X server's access control is disabled (e.g.
KritikCVSS 10,0SilahlaştırılmışEPSS %21x.org · x111 Tem 1997
- CVE-2004-091443Planlayın
Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2)
KritikCVSS 10,0İstismar yokEPSS %9lesstif · lesstif10 Oca 2005
- CVE-2021-3153542Planlayın
LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code.
KritikCVSS 9,8İstismar yokEPSS %11x.org · libx1127 May 2021
- CVE-2018-1460042Planlayın
An issue was discovered in libX11 through 1.6.5.
KritikCVSS 9,8İstismar yokEPSS %9x.org · libx1124 Ağu 2018
- CVE-2016-1016441Planlayın
Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attack
KritikCVSS 9,8İstismar yokEPSS %8x.org · libxpm1 Şub 2017
- CVE-2006-610241Planlayın
Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allow
KritikCVSS 10,0İstismar yokEPSS %3x.org · x.org31 Ara 2006
- CVE-2012-211841Planlayın
Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service o
KritikCVSS 10,0İstismar yokEPSS %3x.org · x1118 May 2012
- CVE-2018-1459940Planlayın
An issue was discovered in libX11 through 1.6.5.
KritikCVSS 9,8İstismar yokEPSS %5x.org · libx1124 Ağu 2018
- CVE-2016-540740Planlayın
The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memo
KritikCVSS 9,8İstismar yokEPSS %5x.org · libxv13 Ara 2016
- CVE-2017-1217740Planlayın
xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X ser
KritikCVSS 9,8İstismar yokEPSS %4debian · debian linux24 Oca 2018
- CVE-2017-1217940Planlayın
xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to
KritikCVSS 9,8İstismar yokEPSS %4debian · debian linux24 Oca 2018
- CVE-2017-1218640Planlayın
xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash o
KritikCVSS 9,8İstismar yokEPSS %4debian · debian linux24 Oca 2018
- CVE-2016-794240Planlayın
The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geo
KritikCVSS 9,8İstismar yokEPSS %4x.org · libx1113 Ara 2016
- CVE-2016-794340Planlayın
The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, wh
KritikCVSS 9,8İstismar yokEPSS %4x.org · libx1113 Ara 2016
- CVE-2017-1218340Planlayın
xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or po
KritikCVSS 9,8İstismar yokEPSS %4debian · debian linux24 Oca 2018
- CVE-2017-1218240Planlayın
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash
KritikCVSS 9,8İstismar yokEPSS %4debian · debian linux24 Oca 2018
- CVE-2017-1218040Planlayın
xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to cra
KritikCVSS 9,8İstismar yokEPSS %4debian · debian linux24 Oca 2018
- CVE-2017-1218140Planlayın
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash
KritikCVSS 9,8İstismar yokEPSS %4debian · debian linux24 Oca 2018
- CVE-2017-1218540Planlayın
xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to c
KritikCVSS 9,8İstismar yokEPSS %4debian · debian linux24 Oca 2018
- CVE-2017-1218440Planlayın
xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or
KritikCVSS 9,8İstismar yokEPSS %4debian · debian linux24 Oca 2018
- CVE-2017-1217640Planlayın
xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X
KritikCVSS 9,8İstismar yokEPSS %4debian · debian linux24 Oca 2018
- CVE-2017-1217840Planlayın
xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server t
KritikCVSS 9,8İstismar yokEPSS %4debian · debian linux24 Oca 2018
- CVE-2016-794940Planlayın
Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X ser
KritikCVSS 9,8İstismar yokEPSS %4x.org · libxrender13 Ara 2016
- CVE-2016-794840Planlayın
X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.
KritikCVSS 9,8İstismar yokEPSS %4x.org · libxrandr13 Ara 2016
- CVE-2016-794740Planlayın
Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted re
KritikCVSS 9,8İstismar yokEPSS %4x.org · libxrandr13 Ara 2016