Show filters
146 Total Results
Displaying 101-110 of 146
Sort by:
Attacker Value
Unknown

CVE-2014-8094

Disclosure Date: December 10, 2014 (last updated October 05, 2023)
Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write.
0
Attacker Value
Unknown

CVE-2011-4613

Disclosure Date: February 05, 2014 (last updated October 05, 2023)
The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restrictions by associating stdin with a file that is misinterpreted as the console TTY.
0
Attacker Value
Unknown

CVE-2013-2066

Disclosure Date: June 15, 2013 (last updated October 05, 2023)
Buffer overflow in X.org libXv 1.0.7 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XvQueryPortAttributes function.
0
Attacker Value
Unknown

CVE-2013-1998

Disclosure Date: June 15, 2013 (last updated October 05, 2023)
Multiple buffer overflows in X.org libXi 1.7.1 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XGetDeviceButtonMapping, (2) XIPassiveGrabDevice, and (3) XQueryDeviceState functions.
0
Attacker Value
Unknown

CVE-2013-1995

Disclosure Date: June 15, 2013 (last updated October 05, 2023)
X.org libXi 1.7.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to an unexpected sign extension in the XListInputDevices function.
0
Attacker Value
Unknown

CVE-2013-1984

Disclosure Date: June 15, 2013 (last updated October 05, 2023)
Multiple integer overflows in X.org libXi 1.7.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XGetDeviceControl, (2) XGetFeedbackControl, (3) XGetDeviceDontPropagateList, (4) XGetDeviceMotionEvents, (5) XIGetProperty, (6) XIGetSelectedEvents, (7) XGetDeviceProperties, and (8) XListInputDevices functions.
0
Attacker Value
Unknown

CVE-2010-4818

Disclosure Date: September 05, 2012 (last updated October 05, 2023)
The GLX extension in X.Org xserver 1.7.7 allows remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary code via (1) a crafted request that triggers a client swap in glx/glxcmdsswap.c; or (2) a crafted length or (3) a negative value in the screen field in a request to glx/glxcmds.c.
0
Attacker Value
Unknown

CVE-2011-4029

Disclosure Date: July 03, 2012 (last updated October 04, 2023)
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution permission) via a symlink attack on a temporary lock file.
0
Attacker Value
Unknown

CVE-2011-4028

Disclosure Date: July 03, 2012 (last updated October 04, 2023)
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a symlink attack on a temporary lock file, which is handled differently if the file exists.
0
Attacker Value
Unknown

CVE-2012-2118

Disclosure Date: May 18, 2012 (last updated October 04, 2023)
Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in an input device name.
0