Vulnerabilities > X ORG > Xorg Server

DATE CVE VULNERABILITY TITLE RISK
2015-07-01 CVE-2015-3164 Permissions, Privileges, and Access Controls vulnerability in multiple products
The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.
local
low complexity
opensuse x-org CWE-264
3.6
2015-02-13 CVE-2015-0255 Information Exposure vulnerability in multiple products
X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string length value in a XkbSetGeometry request.
network
low complexity
x-org opensuse CWE-200
6.4
2007-09-11 CVE-2007-4730 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in X.Org Xorg-Server
Buffer overflow in the compNewPixmap function in compalloc.c in the Composite extension for the X.org X11 server before 1.4 allows local users to execute arbitrary code by copying data from a large pixel depth pixmap into a smaller pixel depth pixmap.
local
low complexity
x-org CWE-119
4.3
2006-08-30 CVE-2006-4447 Local Privilege Escalation vulnerability in Multiple X.Org Products SetUID
X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit.
local
low complexity
x-org
7.2