Vulnerability index

Browse CVEs

49 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xserver HIGH 9.3
CVE-2007-5760

Array index error in the XFree86-Misc extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via a Pass…

Fix: after 1.4
Fix from $1,950 2008-01-18
Evi HIGH 9.3
CVE-2007-6429

Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request …

Fix: after 1.4
Fix from $1,950 2008-01-18
Xserver MEDIUM 5.0
CVE-2007-5958EPSS 5%

X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X progra…

Fix: after 1.4
Fix from $1,600 2008-01-18
Tog Cup MEDIUM 5.0
CVE-2007-6428

The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the con…

Fix: after 1.4
Fix from $1,600 2008-01-18
X Font Server HIGH 7.5
CVE-2007-4990EPSS 11%

The swap_char2b function in X.Org X Font Server (xfs) before 1.0.5 allows context-dependent attackers to execute arbitrary code via (1) QueryXBitmaps…

Fix: after 1.0.4
Fix from $1,950 2007-10-05
X Font Server MEDIUM 6.8
CVE-2007-4568

Integer overflow in the build_range function in X.Org X Font Server (xfs) before 1.0.5 allows context-dependent attackers to execute arbitrary code v…

Patch available
Fix from $1,600 2007-10-05
X Window System MEDIUM 5.5
CVE-2007-2437

The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to cau…

Fix: after 1.3.0
Fix from $1,600 2007-05-02
X11 HIGH 9.0
CVE-2007-1003EPSS 5%

Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and oth…

Patch available
Fix from $1,950 2007-04-06
X.org HIGH 10.0
CVE-2006-6102

Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local u…

Patch available
Fix from $1,950 2006-12-31
X.org MEDIUM 6.6
CVE-2006-6101

Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local…

Patch available
Fix from $1,600 2006-12-31
X.org MEDIUM 6.6
CVE-2006-6103

Integer overflow in the ProcDbeSwapBuffers function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local use…

Patch available
Fix from $1,600 2006-12-31
X.org HIGH 7.2
CVE-2006-3739

Integer overflow in the CIDAFM function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted Adobe Font Metri…

Patch available
Fix from $1,950 2006-09-13
X.org HIGH 7.2
CVE-2006-3740

Integer overflow in the scan_cidfont function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted (1) CMap a…

Patch available
Fix from $1,950 2006-09-13
Emu Linux X87 Xlibs HIGH 7.2
CVE-2006-4447

X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls whe…

Patch available
Fix from $1,950 2006-08-30
X.org MEDIUM 5.0
CVE-2006-0197

The XClientMessageEvent struct used in certain components of X.Org 6.8.2 and earlier, possibly including (1) the X server and (2) Xlib, uses a "long"…

Fix: after 6.8.2
Fix from $1,600 2006-01-13
X11r6 HIGH 7.5
CVE-2004-0687EPSS 8%

Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm …

Patch available
Fix from $1,950 2004-10-20
X11r6 HIGH 7.5
CVE-2004-0688EPSS 7%

Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) …

Patch available
Fix from $1,950 2004-10-20
X11 MEDIUM 6.2
CVE-1999-0965

Race condition in xterm allows local users to modify arbitrary files via the logging option.

Fix: 5.0+
Fix from $1,600 1997-09-19
X11 HIGH 10.0
CVE-1999-0526EPSS 21%

An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.

Mitigation only
Fix from $1,950 1997-07-01