CVE-2022-49737
- EPSS 0.08%
- Published 16.03.2025 00:00:00
- Last modified 17.03.2025 16:15:17
In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread modifies various data structures used by the input thread without acquiring a lock, aka a race condition. In particular, AttachDevi...
CVE-2024-9632
- EPSS 0.06%
- Published 30.10.2024 08:15:04
- Last modified 04.08.2025 21:15:29
A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payload, leading to denial of service or local privilege ...
CVE-2024-31080
- EPSS 0.12%
- Published 04.04.2024 14:15:10
- Last modified 04.08.2025 21:15:28
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, part...
CVE-2024-31081
- EPSS 0.12%
- Published 04.04.2024 14:15:10
- Last modified 04.08.2025 21:15:29
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, part...
CVE-2024-31082
- EPSS 0.03%
- Published 04.04.2024 14:15:10
- Last modified 21.11.2024 09:12:49
A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, par...
CVE-2024-21885
- EPSS 0.24%
- Published 28.02.2024 13:15:08
- Last modified 04.08.2025 21:15:28
A flaw was found in X.Org server. In the XISendDeviceHierarchyEvent function, it is possible to exceed the allocated array length when certain new device IDs are added to the xXIHierarchyInfo struct. This can trigger a heap buffer overflow condition,...
CVE-2007-5760
- EPSS 3.92%
- Published 18.01.2008 23:00:00
- Last modified 09.04.2025 00:30:58
Array index error in the XFree86-Misc extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via a PassMessage request containing a large array index.
- EPSS 4.56%
- Published 18.01.2008 23:00:00
- Last modified 09.04.2025 00:30:58
X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different error messages depending on whether the filename exists.
- EPSS 2.95%
- Published 18.01.2008 23:00:00
- Last modified 09.04.2025 00:30:58
The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request containing a 32-bit value that is improperly used a...
CVE-2007-6429
- EPSS 2.27%
- Published 18.01.2008 23:00:00
- Last modified 09.04.2025 00:30:58
Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by ...