Vulnerabilities > X ORG

DATE CVE VULNERABILITY TITLE RISK
2006-03-21 CVE-2006-0745 Local Privilege Escalation vulnerability in X.Org X Window Server
X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.
local
low complexity
x-org mandrakesoft redhat sun suse
7.2
2006-01-13 CVE-2006-0197 Denial-Of-Service vulnerability in X.org
The XClientMessageEvent struct used in certain components of X.Org 6.8.2 and earlier, possibly including (1) the X server and (2) Xlib, uses a "long" specifier for elements of the l array, which results in inconsistent sizes in the struct on 32-bit versus 64-bit platforms, and might allow attackers to cause a denial of service (application crash) and possibly conduct other attacks.
network
low complexity
x-org
5.0
2005-03-02 CVE-2005-0605 Integer Overflow vulnerability in libXPM Bitmap_unit
scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.
7.5
2005-01-10 CVE-2004-0914 Multiple Unspecified vulnerability in LibXPM
Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file.
network
low complexity
lesstif x-org xfree86-project gentoo redhat suse
critical
10.0
2004-10-20 CVE-2004-0688 Remote Buffer Overflow vulnerability in libXpm Image Decoding
Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.
network
low complexity
x-org xfree86-project openbsd suse
7.5
2004-08-18 CVE-2004-0419 XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.
network
low complexity
x-org xfree86-project gentoo
7.5
1997-09-19 CVE-1999-0965 Unspecified vulnerability in X.Org Xterm
Race condition in xterm allows local users to modify arbitrary files via the logging option.
local
high complexity
x-org
6.2
1997-07-01 CVE-1999-0526 Unspecified vulnerability in X.Org X11 7.11.1.0
An X server's access control is disabled (e.g.
network
low complexity
x-org
critical
10.0