Vulnerability index

Browse CVEs

49 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

X Server HIGH 7.8
CVE-2026-55999

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a …

Fix: 21.2.24 / 24.1.13+
Fix from $1,950 2026-07-08
X Server HIGH 7.8
CVE-2026-56000

Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a H…

Fix: 21.2.24 / 24.1.13+
Fix from $1,950 2026-07-08
Libxpm HIGH 8.8
CVE-2022-4883

A flaw was found in libXpm. When processing files with .Z or .gz extensions, the library calls external programs to compress and uncompress files, re…

Fix: 3.5.15+
Fix from $1,950 2023-02-07
Libxpm HIGH 7.5
CVE-2022-46285

A flaw was found in libXpm. This issue occurs when parsing a file with a comment not closed; the end-of-file condition will not be detected, leading …

Fix: 3.5.15+
Fix from $1,950 2023-02-07
Libxpm HIGH 7.5
CVE-2022-44617

A flaw was found in libXpm. When processing a file with width of 0 and a very large height, some parser functions will be called repeatedly and can l…

Fix: 3.5.15+
Fix from $1,950 2023-02-06
X Server MEDIUM 6.5
CVE-2022-3553

A vulnerability, which was classified as problematic, was found in X.org Server. This affects an unknown part of the file hw/xquartz/X11Controller.m …

Patch available
Fix from $1,600 2022-10-17
X Server HIGH 7.8
CVE-2022-2319

A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur in the ProcXkbSetGeometry function due to improper validation of the…

Patch available
Fix from $1,950 2022-09-01
X Server HIGH 7.8
CVE-2022-2320

A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the la…

Patch available
Fix from $1,950 2022-09-01
X Server HIGH 7.0
CVE-2020-25697

A privilege escalation flaw was found in the Xorg-x11-server due to a lack of authentication for X11 clients. This flaw allows an attacker to take co…

Mitigation only
Fix from $1,950 2021-05-26
X Server HIGH 7.8
CVE-2020-14360

A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead to a privilege escalation vul…

Fix: 1.20.10+
Fix from $1,950 2021-01-20
X Server HIGH 7.8
CVE-2019-17624

"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sending ct.c_char 1000 times, an at…

Fix: after 1.20.4
Fix from $1,950 2019-10-16
Libxfont HIGH 7.1
CVE-2017-13720

In the PatternMatch function in fontfile/fontdir.c in libXfont through 1.5.2 and 2.x before 2.0.2, an attacker with access to an X connection can cau…

Fix: after 1.5.2
Fix from $1,950 2017-10-11
Libxfont HIGH 7.1
CVE-2017-13722

In the pcfGetProperties function in bitmap/pcfread.c in libXfont through 1.5.2 and 2.x before 2.0.2, a missing boundary check (for PCF files) could b…

Fix: after 1.5.2
Fix from $1,950 2017-10-11
X Server HIGH 8.8
CVE-2017-10971

In the X.Org X server before 2017-06-19, a user authenticated to an X Session could crash or execute code in the context of the X Server by exploitin…

Fix: after 1.19.3
Fix from $1,950 2017-07-06
X Server MEDIUM 6.5
CVE-2017-10972

Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to a…

Fix: after 1.19.3
Fix from $1,600 2017-07-06
Libxpm CRITICAL 9.8
CVE-2016-10164EPSS 8%

Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to ca…

Fix: after 3.5.11
Fix from $2,300 2017-02-01
X Server HIGH 7.5
CVE-2015-3418

The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service…

Fix: after 1.16.3
Fix from $1,950 2016-12-13
X Server MEDIUM 6.4
CVE-2015-0255

X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from proces…

Fix: after 1.16.3
Fix from $1,600 2015-02-13
X Server MEDIUM 6.5
CVE-2014-8103

X.Org Server (aka xserver and xorg-server) 1.15.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (out-of…

Patch available
Fix from $1,600 2014-12-10
Xfree86 MEDIUM 6.5
CVE-2014-8100

The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 all…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
Xfree86 MEDIUM 6.5
CVE-2014-8101

The RandR extension in XFree86 4.2.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allo…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
X11 MEDIUM 6.5
CVE-2014-8099

The XVideo extension in XFree86 4.0.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 all…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
X Server MEDIUM 6.5
CVE-2014-8097

The DBE extension in X.Org X Window System (aka X11 or X) X11R6.1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenti…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
X11 MEDIUM 6.5
CVE-2014-8093

Multiple integer overflows in the GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-…

Fix: after 1.16.2
Fix from $1,600 2014-12-10
X11 MEDIUM 6.5
CVE-2014-8092

Multiple integer overflows in X.Org X Window System (aka X11 or X) X11R1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote au…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
Libxi MEDIUM 6.8
CVE-2013-1995

X.org libXi 1.7.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to an unexpecte…

Fix: after 1.7.1
Fix from $1,600 2013-06-15
Libxi MEDIUM 6.8
CVE-2013-1998

Multiple buffer overflows in X.org libXi 1.7.1 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code v…

Fix: after 1.7.1
Fix from $1,600 2013-06-15
Libxi MEDIUM 6.8
CVE-2013-1984

Multiple integer overflows in X.org libXi 1.7.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via ve…

Fix: after 1.7.1
Fix from $1,600 2013-06-15
X.org HIGH 8.5
CVE-2010-4818EPSS 5%

The GLX extension in X.Org xserver 1.7.7 allows remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary…

Patch available
Fix from $1,950 2012-09-05
X11 HIGH 10.0
CVE-2012-2118

Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibl…

Patch available
Fix from $1,950 2012-05-18