CVE-2014-8091
- EPSS 4.84%
- Veröffentlicht 10.12.2014 15:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver and xorg-server) before 1.16.3, when using SUN-DES-1 (Secure RPC) authentication credentials, does not check the return value of a malloc call, which allows remote attackers to...
CVE-2011-4613
- EPSS 0.08%
- Veröffentlicht 05.02.2014 19:55:28
- Zuletzt bearbeitet 29.04.2026 01:13:23
The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restrictions by associating stdin with a file that is misint...
CVE-2011-4029
- EPSS 0.77%
- Veröffentlicht 03.07.2012 19:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution permission) via a symlink attack ...
CVE-2011-4028
- EPSS 0.1%
- Veröffentlicht 03.07.2012 19:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a symlink attack on a temporary lock file, which is handled differently if the file exists.
CVE-2007-6427
- EPSS 4.24%
- Veröffentlicht 18.01.2008 23:00:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.