Show filters
146 Total Results
Displaying 51-60 of 146
Sort by:
Attacker Value
Unknown
CVE-2018-14600
Disclosure Date: August 24, 2018 (last updated November 27, 2024)
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resulting in an out-of-bounds write (of up to 128 bytes), leading to DoS or remote code execution.
0
Attacker Value
Unknown
CVE-2017-2624
Disclosure Date: July 27, 2018 (last updated November 27, 2024)
It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.
0
Attacker Value
Unknown
CVE-2017-2625
Disclosure Date: July 27, 2018 (last updated November 27, 2024)
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.
0
Attacker Value
Unknown
CVE-2017-12180
Disclosure Date: January 24, 2018 (last updated November 26, 2024)
xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
0
Attacker Value
Unknown
CVE-2017-12179
Disclosure Date: January 24, 2018 (last updated November 26, 2024)
xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
0
Attacker Value
Unknown
CVE-2017-12187
Disclosure Date: January 24, 2018 (last updated November 26, 2024)
xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
0
Attacker Value
Unknown
CVE-2017-12184
Disclosure Date: January 24, 2018 (last updated November 26, 2024)
xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
0
Attacker Value
Unknown
CVE-2017-12185
Disclosure Date: January 24, 2018 (last updated November 26, 2024)
xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
0
Attacker Value
Unknown
CVE-2017-12178
Disclosure Date: January 24, 2018 (last updated November 26, 2024)
xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
0
Attacker Value
Unknown
CVE-2017-12183
Disclosure Date: January 24, 2018 (last updated November 26, 2024)
xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
0