Vulnerabilities > X

DATE CVE VULNERABILITY TITLE RISK
2014-05-15 CVE-2014-0210 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Multiple buffer overflows in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs protocol reply to the (1) _fs_recv_conn_setup, (2) fs_read_open_font, (3) fs_read_query_info, (4) fs_read_extent_info, (5) fs_read_glyphs, (6) fs_read_list, or (7) fs_read_list_info function.
network
low complexity
x canonical CWE-119
7.5
2014-05-15 CVE-2014-0209 Numeric Errors vulnerability in multiple products
Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a directory with a large fonts.dir or fonts.alias file to the font path, which triggers a heap-based buffer overflow, related to metadata.
local
low complexity
x canonical CWE-189
4.6
2014-02-10 CVE-2012-0064 Permissions, Privileges, and Access Controls vulnerability in multiple products
xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physically proximate attackers to bypass an X screen lock via keyboard combinations that break the input grab.
local
low complexity
x xkeyboard-config-project CWE-264
4.6
2014-01-09 CVE-2013-6462 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in X Libxfont
Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.
network
x CWE-119
critical
9.3
2013-12-27 CVE-2013-2179 Cryptographic Issues vulnerability in X Display Manager 1.1.10/1.1.11
X.Org xdm 1.1.10, 1.1.11, and possibly other versions, when performing authentication using certain implementations of the crypt API function that can return NULL, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by attempting to log into an account whose password field contains invalid characters, as demonstrated using the crypt function from glibc 2.17 and later with (1) the "!" character in the salt portion of a password field or (2) a password that has been encrypted using DES or MD5 in FIPS-140 mode.
network
x CWE-310
4.3
2013-10-10 CVE-2013-4396 Resource Management Errors vulnerability in X X.Org X11
Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure.
network
low complexity
x CWE-399
6.5
2013-06-15 CVE-2013-2066 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Buffer overflow in X.org libXv 1.0.7 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XvQueryPortAttributes function.
network
x x-org CWE-119
6.8
2013-06-15 CVE-2013-2005 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in X Libxt
X.org libXt 1.1.3 and earlier does not check the return value of the XGetWindowProperty function, which allows X servers to trigger use of an uninitialized pointer and memory corruption via vectors related to the (1) ReqCleanup, (2) HandleSelectionEvents, (3) ReqTimedOut, (4) HandleNormal, and (5) HandleSelectionReplies functions.
network
x CWE-119
6.8
2013-06-15 CVE-2013-2004 Buffer Errors vulnerability in X Libx11 1.5.0/1.5.99.901
The (1) GetDatabase and (2) _XimParseStringFile functions in X.org libX11 1.5.99.901 (1.6 RC1) and earlier do not restrict the recursion depth when processing directives to include files, which allows X servers to cause a denial of service (stack consumption) via a crafted file.
network
x CWE-119
6.8
2013-06-15 CVE-2013-2003 Numeric Errors vulnerability in X Libxcursor
Integer overflow in X.org libXcursor 1.1.13 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the _XcursorFileHeaderCreate function.
network
x CWE-189
6.8