Show filters
146 Total Results
Displaying 51-60 of 146
Sort by:
Attacker Value
Unknown

CVE-2018-14600

Disclosure Date: August 24, 2018 (last updated November 27, 2024)
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resulting in an out-of-bounds write (of up to 128 bytes), leading to DoS or remote code execution.
0
Attacker Value
Unknown

CVE-2017-2624

Disclosure Date: July 27, 2018 (last updated November 27, 2024)
It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.
0
Attacker Value
Unknown

CVE-2017-2625

Disclosure Date: July 27, 2018 (last updated November 27, 2024)
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.
0
Attacker Value
Unknown

CVE-2017-12180

Disclosure Date: January 24, 2018 (last updated November 26, 2024)
xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
0
Attacker Value
Unknown

CVE-2017-12179

Disclosure Date: January 24, 2018 (last updated November 26, 2024)
xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
0
Attacker Value
Unknown

CVE-2017-12187

Disclosure Date: January 24, 2018 (last updated November 26, 2024)
xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
0
Attacker Value
Unknown

CVE-2017-12184

Disclosure Date: January 24, 2018 (last updated November 26, 2024)
xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
0
Attacker Value
Unknown

CVE-2017-12185

Disclosure Date: January 24, 2018 (last updated November 26, 2024)
xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
0
Attacker Value
Unknown

CVE-2017-12178

Disclosure Date: January 24, 2018 (last updated November 26, 2024)
xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
0
Attacker Value
Unknown

CVE-2017-12183

Disclosure Date: January 24, 2018 (last updated November 26, 2024)
xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
0