Vulnerabilities > X > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-12-01 CVE-2017-16612 Integer Overflow or Wraparound vulnerability in multiple products
libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP.
network
low complexity
debian canonical x CWE-190
5.0
2017-12-01 CVE-2017-16611 Link Following vulnerability in multiple products
In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.
local
low complexity
debian canonical x CWE-59
4.9
2014-07-24 CVE-2014-4910 Path Traversal vulnerability in X Xf86-Video-Intel 2.99.911
Directory traversal vulnerability in tools/backlight_helper.c in X.Org xf86-video-intel 2.99.911 allows remote attackers to create or overwrite arbitrary files via a ..
local
low complexity
x CWE-22
4.6
2014-05-15 CVE-2014-0209 Numeric Errors vulnerability in multiple products
Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a directory with a large fonts.dir or fonts.alias file to the font path, which triggers a heap-based buffer overflow, related to metadata.
local
low complexity
x canonical CWE-189
4.6
2014-02-10 CVE-2012-0064 Permissions, Privileges, and Access Controls vulnerability in multiple products
xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physically proximate attackers to bypass an X screen lock via keyboard combinations that break the input grab.
local
low complexity
x xkeyboard-config-project CWE-264
4.6
2013-12-27 CVE-2013-2179 Cryptographic Issues vulnerability in X Display Manager 1.1.10/1.1.11
X.Org xdm 1.1.10, 1.1.11, and possibly other versions, when performing authentication using certain implementations of the crypt API function that can return NULL, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by attempting to log into an account whose password field contains invalid characters, as demonstrated using the crypt function from glibc 2.17 and later with (1) the "!" character in the salt portion of a password field or (2) a password that has been encrypted using DES or MD5 in FIPS-140 mode.
network
x CWE-310
4.3
2013-10-10 CVE-2013-4396 Resource Management Errors vulnerability in X X.Org X11
Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure.
network
low complexity
x CWE-399
6.5
2013-06-15 CVE-2013-2066 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Buffer overflow in X.org libXv 1.0.7 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XvQueryPortAttributes function.
network
x x-org CWE-119
6.8
2013-06-15 CVE-2013-2005 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in X Libxt
X.org libXt 1.1.3 and earlier does not check the return value of the XGetWindowProperty function, which allows X servers to trigger use of an uninitialized pointer and memory corruption via vectors related to the (1) ReqCleanup, (2) HandleSelectionEvents, (3) ReqTimedOut, (4) HandleNormal, and (5) HandleSelectionReplies functions.
network
x CWE-119
6.8
2013-06-15 CVE-2013-2004 Buffer Errors vulnerability in X Libx11 1.5.0/1.5.99.901
The (1) GetDatabase and (2) _XimParseStringFile functions in X.org libX11 1.5.99.901 (1.6 RC1) and earlier do not restrict the recursion depth when processing directives to include files, which allows X servers to cause a denial of service (stack consumption) via a crafted file.
network
x CWE-119
6.8