Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
x.org x server vulnerabilities and exploits
(subscribe to this query)
9.3
CVSSv2
CVE-2011-0465
xrdb.c in xrdb prior to 1.0.9 in X.Org X11R7.6 and previous versions allows remote malicious users to execute arbitrary commands via shell metacharacters in a hostname obtained from a (1) DHCP or (2) XDMCP message.
X X11
X X11 R7.5
Matthias Hopf Xrdb 1.0.6
Matthias Hopf Xrdb 1.0.5
Matthias Hopf Xrdb 1.0.4
X X11 R6.8.0
X X11 R6.7.0
X X11 R6
X X11 R5
Matthias Hopf Xrdb
Matthias Hopf Xrdb 1.0.7
X X11 R6.8.2
X X11 R6.8.1
X X11 R6.3
X X11 R6.1
X X11 R7.2
X X11 R7.1
X X11 R7.0
X X11 R6.9.0
X X11 R6.5.1
X X11 R6.4
X X11 R2
4.9
CVSSv2
CVE-2010-3448
drivers/platform/x86/thinkpad_acpi.c in the Linux kernel prior to 2.6.34 on ThinkPad devices, when the X.Org X server is used, does not properly restrict access to the video output control state, which allows local users to cause a denial of service (system hang) via a (1) read o...
Linux Linux Kernel
7.2
CVSSv2
CVE-2010-2240
The do_anonymous_page function in mm/memory.c in the Linux kernel prior to 2.6.27.52, 2.6.32.x prior to 2.6.32.19, 2.6.34.x prior to 2.6.34.4, and 2.6.35.x prior to 2.6.35.2 does not properly separate the stack and the heap, which allows context-dependent malicious users to execu...
Linux Linux Kernel 2.6.32.5
Linux Linux Kernel 2.6.35.1
Linux Linux Kernel 2.6.32.12
Linux Linux Kernel 2.6.32.9
Linux Linux Kernel 2.6.32
Linux Linux Kernel 2.6.32.3
Linux Linux Kernel 2.6.32.17
Linux Linux Kernel 2.6.34.1
Linux Linux Kernel 2.6.32.11
Linux Linux Kernel
Linux Linux Kernel 2.6.32.14
Linux Linux Kernel 2.6.32.6
Linux Linux Kernel 2.6.32.15
Linux Linux Kernel 2.6.32.18
Linux Linux Kernel 2.6.32.4
Linux Linux Kernel 2.6.32.16
Linux Linux Kernel 2.6.34.3
Linux Linux Kernel 2.6.32.7
Linux Linux Kernel 2.6.32.8
Linux Linux Kernel 2.6.32.2
Linux Linux Kernel 2.6.32.1
Linux Linux Kernel 2.6.34.2
7.1
CVSSv2
CVE-2010-1166
The fbComposite function in fbpict.c in the Render extension in the X server in X.Org X11R7.1 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted request, related to an incorrect macr...
X X.org 7.1
9
CVSSv2
CVE-2008-1377
The (1) SProcRecordCreateContext and (2) SProcRecordRegisterClients functions in the Record extension and the (3) SProcSecurityGenerateAuthorization function in the Security extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent malicious users to execute arbitrar...
X X11 R7.3
6.8
CVSSv2
CVE-2008-1379
Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent malicious users to read arbitrary process memory via crafted values for a Pixmap width and height.
X X11 R7.3
9
CVSSv2
CVE-2008-2360
Integer overflow in the AllocateGlyph function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent malicious users to execute arbitrary code via unspecified request fields that are used to calculate a heap buffer size, which triggers a heap-based...
X X11 R7.3
6.8
CVSSv2
CVE-2008-2361
Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent malicious users to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size,...
Xorg X11 R7.3
10
CVSSv2
CVE-2008-2362
Multiple integer overflows in the Render extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent malicious users to execute arbitrary code via a (1) SProcRenderCreateLinearGradient, (2) SProcRenderCreateRadialGradient, or (3) SProcRenderCreateConicalGradient reques...
X X11 R7.3
5
CVSSv2
CVE-2007-5958
X.Org Xserver prior to 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different error messages depending on whether the filename exists.
X.org Xserver
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
cross-site scripting
CVE-2024-5158
XML external entity
CVE-2024-4262
CVE-2024-2036
CVE-2024-4985
CVE-2024-21791
remote attackers
CVE-2023-43208
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »