pkg:Debian/xorg-server

184 total CVEsCRITICAL19HIGH92MEDIUM14

✅ Check your installed version

All known vulnerabilities

  • CRITICAL9.8CVE-2023-6816xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u11
  • CRITICAL9.8CVE-2023-6816xorg-server - security update
    from 0, < 2:1.20.4-1+deb10u13
  • CRITICAL9.8CVE-2023-6816xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u11
  • CRITICAL9.8CVE-2017-12187xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or p…
    from 0, < 2:1.19.5-1
  • CRITICAL9.8CVE-2017-12186xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash…
    from 0, < 2:1.19.5-1
  • CRITICAL9.8CVE-2017-12185xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to…
    from 0, < 2:1.19.5-1
  • CRITICAL9.8CVE-2017-12184xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or…
    from 0, < 2:1.19.5-1
  • CRITICAL9.8CVE-2017-12183xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or p…
    from 0, < 2:1.19.5-1
  • CRITICAL9.8CVE-2017-12182xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash…
    from 0, < 2:1.19.5-1
  • CRITICAL9.8CVE-2017-12181xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash…
    from 0, < 2:1.19.5-1
  • CRITICAL9.8CVE-2017-12180xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to cr…
    from 0, < 2:1.19.5-1
  • CRITICAL9.8CVE-2017-12179xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to…
    from 0, < 2:1.19.5-1
  • CRITICAL9.8CVE-2017-12178xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server…
    from 0, < 2:1.19.5-1
  • CRITICAL9.8CVE-2017-12177xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X se…
    from 0, < 2:1.19.5-1
  • CRITICAL9.8CVE-2017-12176xorg-server - security update
    from 0, < 2:1.19.5-1
  • CRITICAL9.8CVE-2017-12176xorg-server - security update
    from 0, < 2:1.16.4-1+deb8u2
  • CRITICAL9.8CVE-2017-12176xorg-server - security update
    from 0, < 2:1.12.4-6+deb7u8
  • CRITICAL9.1CVE-2026-34002A flaw was found in the X.Org X server.
    from 0
  • CRITICAL9.1CVE-2026-34000A flaw was found in the X.Org X server.
    from 0
  • HIGH8.8CVE-2022-46344A vulnerability was found in X.Org.
    from 0, < 2:1.20.11-1+deb11u4
  • HIGH8.8CVE-2022-46343A vulnerability was found in X.Org.
    from 0, < 2:1.20.11-1+deb11u4
  • HIGH8.8CVE-2022-46342A vulnerability was found in X.Org.
    from 0, < 2:1.20.11-1+deb11u4
  • HIGH8.8CVE-2022-46341A vulnerability was found in X.Org.
    from 0, < 2:1.20.11-1+deb11u4
  • HIGH8.8CVE-2022-46340A vulnerability was found in X.Org.
    from 0, < 2:1.20.11-1+deb11u4
  • HIGH8.8CVE-2022-3550xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u3
  • HIGH8.8CVE-2022-3550xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u3
  • HIGH8.8CVE-2022-3550xorg-server - security update
    from 0, < 2:1.20.4-1+deb10u6
  • HIGH8.8CVE-2017-10971xorg-server - security update
    from 0, < 2:1.19.3-2
  • HIGH8.8CVE-2017-10971xorg-server - security update
    from 0, < 2:1.16.4-1+deb8u1
  • HIGH8.8CVE-2017-10971xorg-server - security update
    from 0, < 2:1.12.4-6+deb7u7
  • HIGH7.8CVE-2026-34003A flaw was found in the X.Org X server's XKB key types request validation.
    from 0
  • HIGH7.8CVE-2026-34001A flaw was found in the X.Org X server.
    from 0
  • HIGH7.8CVE-2026-33999A flaw was found in the X.Org X server.
    from 0
  • HIGH7.8CVE-2025-49180A flaw was found in the RandR extension, where the RRChangeProviderProperty function does not properly validate input.
    from 0, < 2:1.20.11-1+deb11u16
  • HIGH7.8CVE-2025-26601A use-after-free flaw was found in X.Org and Xwayland.
    from 0, < 2:1.20.11-1+deb11u15
  • HIGH7.8CVE-2025-26600A use-after-free flaw was found in X.Org and Xwayland.
    from 0, < 2:1.20.11-1+deb11u15
  • HIGH7.8CVE-2025-26599An access to an uninitialized pointer flaw was found in X.Org and Xwayland.
    from 0, < 2:1.20.11-1+deb11u15
  • HIGH7.8CVE-2025-26598An out-of-bounds write flaw was found in X.Org and Xwayland.
    from 0, < 2:1.20.11-1+deb11u15
  • HIGH7.8CVE-2025-26597A buffer overflow flaw was found in X.Org and Xwayland.
    from 0, < 2:1.20.11-1+deb11u15
  • HIGH7.8CVE-2025-26596A heap overflow flaw was found in X.Org and Xwayland.
    from 0, < 2:1.20.11-1+deb11u15
  • HIGH7.8CVE-2025-26595A buffer overflow flaw was found in X.Org and Xwayland.
    from 0, < 2:1.20.11-1+deb11u15
  • HIGH7.8CVE-2025-26594xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u15
  • HIGH7.8CVE-2025-26594xorg-server - security update
    from 0, < 2:21.1.7-3+deb12u9
  • HIGH7.8CVE-2025-26594xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u15
  • HIGH7.8CVE-2024-9632xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u14
  • HIGH7.8CVE-2024-9632xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u14
  • HIGH7.8CVE-2024-9632xorg-server - security update
    from 0, < 2:21.1.7-3+deb12u8
  • HIGH7.8CVE-2024-31083A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers.
    from 0, < 2:1.20.11-1+deb11u13
  • HIGH7.8CVE-2024-21886A heap buffer overflow flaw was found in the DisableDevice function in the X.Org server.
    from 0, < 2:1.20.11-1+deb11u11
  • HIGH7.8CVE-2024-21885A flaw was found in X.Org server.
    from 0, < 2:1.20.11-1+deb11u11
  • HIGH7.8CVE-2024-0229An out-of-bounds memory access flaw was found in the X.Org server.
    from 0, < 2:1.20.11-1+deb11u11
  • HIGH7.8CVE-2024-0409A flaw was found in the X.Org server.
    from 0, < 2:1.20.11-1+deb11u11
  • HIGH7.8CVE-2023-6377xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u9
  • HIGH7.8CVE-2023-6377xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u10
  • HIGH7.8CVE-2023-6377xorg-server - security update
    from 0, < 2:1.20.4-1+deb10u11
  • HIGH7.8CVE-2023-6377xorg-server - security update
    from 0, < 2:1.20.4-1+deb10u12
  • HIGH7.8CVE-2023-6377xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u10
  • HIGH7.8CVE-2023-5367xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u8
  • HIGH7.8CVE-2023-5367xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u8
  • HIGH7.8CVE-2023-5367xorg-server - security update
    from 0, < 2:1.20.4-1+deb10u10
  • HIGH7.8CVE-2023-1393xorg-server - security update
    from 0, < 2:1.20.4-1+deb10u9
  • HIGH7.8CVE-2023-1393xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u6
  • HIGH7.8CVE-2023-1393xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u6
  • HIGH7.8CVE-2023-0494xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u5
  • HIGH7.8CVE-2023-0494xorg-server - security update
    from 0, < 2:1.20.4-1+deb10u8
  • HIGH7.8CVE-2023-0494xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u5
  • HIGH7.8CVE-2022-4283xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u4
  • HIGH7.8CVE-2022-4283xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u4
  • HIGH7.8CVE-2022-4283xorg-server - security update
    from 0, < 2:1.20.4-1+deb10u7
  • HIGH7.8CVE-2022-2320A flaw was found in the Xorg-x11-server.
    from 0, < 2:1.20.11-1+deb11u2
  • HIGH7.8CVE-2022-2319xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u2
  • HIGH7.8CVE-2022-2319xorg-server - security update
    from 0, < 2:1.20.4-1+deb10u5
  • HIGH7.8CVE-2022-2319xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u2
  • HIGH7.8CVE-2021-4011A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14.
    from 0, < 2:1.20.11-1+deb11u1
  • HIGH7.8CVE-2021-4010A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14.
    from 0, < 2:1.20.11-1+deb11u1
  • HIGH7.8CVE-2021-4009A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14.
    from 0, < 2:1.20.11-1+deb11u1
  • HIGH7.8CVE-2021-4008xorg-server - security update
    from 0, < 2:1.20.4-1+deb10u4
  • HIGH7.8CVE-2021-4008xorg-server - security update
    from 0, < 2:1.19.2-1+deb9u9
  • HIGH7.8CVE-2021-4008xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u1
  • HIGH7.8CVE-2021-3472xorg-server - security update
    from 0, < 2:1.20.4-1+deb10u3
  • HIGH7.8CVE-2021-3472xorg-server - security update
    from 0, < 2:1.19.2-1+deb9u8
  • HIGH7.8CVE-2021-3472xorg-server - security update
    from 0, < 2:1.20.11-1
  • HIGH7.8CVE-2020-14360xorg-server - security update
    from 0, < 2:1.20.4-1+deb10u2
  • HIGH7.8CVE-2020-14360xorg-server - security update
    from 0, < 2:1.19.2-1+deb9u7
  • HIGH7.8CVE-2020-14360xorg-server - security update
    from 0, < 2:1.20.10-1
  • HIGH7.8CVE-2020-25712A flaw was found in xorg-x11-server before 1.20.10.
    from 0, < 2:1.20.10-1
  • HIGH7.8CVE-2020-14362A flaw was found in X.Org Server before xorg-x11-server 1.20.9.
    from 0, < 2:1.20.9-1
  • HIGH7.8CVE-2020-14361A flaw was found in X.Org Server before xorg-x11-server 1.20.9.
    from 0, < 2:1.20.9-1
  • HIGH7.8CVE-2020-14346A flaw was found in xorg-x11-server before 1.20.9.
    from 0, < 2:1.20.9-1
  • HIGH7.8CVE-2020-14345xorg-server - security update
    from 0, < 2:1.20.9-1
  • HIGH7.8CVE-2020-14345xorg-server - security update
    from 0, < 2:1.20.4-1+deb10u1
  • HIGH7.8CVE-2020-14345xorg-server - security update
    from 0, < 2:1.19.2-1+deb9u6
  • HIGH7.8CVE-2017-13723In X.Org Server (aka xserver and xorg-server) before 1.19.4, a local attacker authenticated to the X server could overflow a global buffer,…
    from 0, < 2:1.19.4-1
  • HIGH7.7CVE-2022-49737In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread modifies various dat…
    from 0
  • HIGH7.5CVE-2023-6478A flaw was found in xorg-server.
    from 0, < 2:1.20.11-1+deb11u9
  • HIGH7.5CVE-2015-3418xorg-server - regression update
    from 0, < 2:1.7.7-18+deb6u3
  • HIGH7.5CVE-2015-3418xorg-server - regression update
    from 0, < 2:1.16.4-1
  • HIGH7.3CVE-2025-62230A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup.
    from 0, < 2:1.20.11-1+deb11u17
  • HIGH7.3CVE-2025-62229xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u17
  • HIGH7.3CVE-2025-62229xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u17
  • HIGH7.3CVE-2025-62229xorg-server - security update
    from 0, < 2:21.1.7-3+deb12u11
  • HIGH7.3CVE-2025-62231A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function c…
    from 0, < 2:1.20.11-1+deb11u17
  • HIGH7.3CVE-2025-49179A flaw was found in the X Record extension.
    from 0, < 2:1.20.11-1+deb11u16
  • HIGH7.3CVE-2025-49176A flaw was found in the Big Requests extension.
    from 0, < 2:1.20.11-1+deb11u16
  • HIGH7.3CVE-2024-31082A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function.
    from 0, < 2:1.20.11-1+deb11u13
  • HIGH7.3CVE-2024-31081A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function.
    from 0, < 2:1.20.11-1+deb11u13
  • HIGH7.3CVE-2024-31080xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u13
  • HIGH7.3CVE-2024-31080xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u13
  • HIGH7.3CVE-2024-31080xorg-server - security update
    from 0, < 2:1.20.4-1+deb10u14
  • HIGH7.0CVE-2023-5574A use-after-free flaw was found in xorg-x11-server-Xvfb.
    from 0
  • HIGH7.0CVE-2017-2624It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies.
    from 0, < 2:1.19.2-1
  • MEDIUM6.6CVE-2018-14665xorg-server - security update
    from 0, < 2:1.19.2-1+deb9u4
  • MEDIUM6.6CVE-2018-14665xorg-server - security update
    from 0, < 2:1.20.3-1
  • MEDIUM6.5CVE-2022-3553A vulnerability, which was classified as problematic, was found in X.org Server.
    from 0
  • MEDIUM6.5CVE-2022-3551A vulnerability, which was classified as problematic, has been found in X.org Server.
    from 0, < 2:1.20.11-1+deb11u3
  • MEDIUM6.5CVE-2017-10972Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious…
    from 0, < 2:1.19.3-2
  • MEDIUM6.1CVE-2025-49177A flaw was found in the XFIXES extension.
    from 0, < 2:21.1.7-3+deb12u10
  • MEDIUM6.1CVE-2025-49175xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u16
  • MEDIUM6.1CVE-2025-49175xorg-server - security update
    from 0, < 2:21.1.7-3+deb12u10
  • MEDIUM6.1CVE-2025-49175xorg-server - security update
    from 0, < 2:1.20.11-1+deb11u16
  • MEDIUM5.5CVE-2025-49178A flaw was found in the X server's request handling.
    from 0, < 2:1.20.11-1+deb11u16
  • MEDIUM5.5CVE-2024-0408A flaw was found in the X.Org server.
    from 0, < 2:1.20.11-1+deb11u11
  • MEDIUM5.5CVE-2020-14347A flaw was found in the way xserver memory was not properly initialized.
    from 0, < 2:1.20.9-1
  • MEDIUM4.7CVE-2023-5380A use-after-free flaw was found in the xorg-x11-server.
    from 0, < 2:1.20.11-1+deb11u8
  • MEDIUM4.7CVE-2017-13721In X.Org Server (aka xserver and xorg-server) before 1.19.4, an attacker authenticated to an X server with the X shared memory extension en…
    from 0, < 2:1.19.4-1
  • CVE-2015-3164The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users…
    from 0, < 2:1.17.2-1
  • CVE-2015-0255xorg-server - security update
    from 0, < 2:1.7.7-18+deb6u2
  • CVE-2015-0255xorg-server - security update
    from 0, < 2:1.12.4-6+deb7u6
  • CVE-2015-0255xorg-server - security update
    from 0, < 2:1.16.4-1
  • CVE-2014-8103X.Org Server (aka xserver and xorg-server) 1.15.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of servi…
    from 0, < 2:1.16.2.901-1
  • CVE-2014-8102The SProcXFixesSelectSelectionInput function in the XFixes extension in X.Org X Window System (aka X11 or X) X11R6.8.0 and X.Org Server (ak…
    from 0, < 2:1.16.2.901-1
  • CVE-2014-8101The RandR extension in XFree86 4.2.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1…
    from 0, < 2:1.16.2.901-1
  • CVE-2014-8100The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before…
    from 0, < 2:1.16.2.901-1
  • CVE-2014-8099The XVideo extension in XFree86 4.0.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before…
    from 0, < 2:1.16.2.901-1
  • CVE-2014-8098The GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.…
    from 0, < 2:1.16.2.901-1
  • CVE-2014-8097The DBE extension in X.Org X Window System (aka X11 or X) X11R6.1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remot…
    from 0, < 2:1.16.2.901-1
  • CVE-2014-8096The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X) X11R6.0 and X.Org Server (aka xserver a…
    from 0, < 2:1.16.2.901-1
  • CVE-2014-8095The XInput extension in X.Org X Window System (aka X11 or X) X11R4 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remo…
    from 0, < 2:1.16.2.901-1
  • CVE-2014-8094Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.…
    from 0, < 2:1.16.2.901-1
  • CVE-2014-8093Multiple integer overflows in the GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver…
    from 0, < 2:1.16.2.901-1
  • CVE-2014-8092Multiple integer overflows in X.Org X Window System (aka X11 or X) X11R1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow…
    from 0, < 2:1.16.2.901-1
  • CVE-2014-8091xorg-server - security update
    from 0, < 2:1.7.7-18+deb6u1
  • CVE-2014-8091xorg-server - security update
    from 0, < 2:1.12.4-6+deb7u5
  • CVE-2014-8091xorg-server - security update
    from 0, < 2:1.16.2.901-1
  • CVE-2012-0064xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physically proximate attac…
    from 0, < 2:1.11.3.901-2
  • CVE-2013-6424xorg-server - integer underflow
    from 0, < 2:1.7.7-18
  • CVE-2013-6424xorg-server - integer underflow
    from 0, < 2:1.14.2.901-1
  • CVE-2013-4396xorg-server - use-after-free
    from 0, < 2:1.7.7-17
  • CVE-2013-4396xorg-server - use-after-free
    from 0, < 2:1.14.3-4
  • CVE-2013-1940xorg-server - information disclosure
    from 0, < 2:1.12.4-6
  • CVE-2013-1940xorg-server - information disclosure
    from 0, < 2:1.7.7-16
  • CVE-2010-4819The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read ar…
    from 0, < 2:1.9.0.901-1
  • CVE-2010-4818The GLX extension in X.Org xserver 1.7.7 allows remote authenticated users to cause a denial of service (server crash) and possibly execute…
    from 0, < 2:1.9.99.902-1
  • CVE-2011-4029The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444…
    from 0, < 2:1.11.1.901-2
  • CVE-2011-4028The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a…
    from 0, < 2:1.11.1.901-2
  • CVE-2012-2118Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service…
    from 0, < 2:1.12.1.902-1
  • CVE-2009-1573xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command…
    from 0, < 2:1.6.1.901-3
  • CVE-2008-1379Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attac…
    from 0, < 2:1.4.1~git20080517-2
  • CVE-2008-1377xorg-server - multiple vulnerabilities
    from 0, < 2:1.1.1-21etch5
  • CVE-2008-1377xorg-server - multiple vulnerabilities
    from 0, < 2:1.4.1~git20080517-2~lenny1
  • CVE-2008-2361Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-depende…
    from 0, < 2:1.4.1~git20080517-2
  • CVE-2008-2360Integer overflow in the AllocateGlyph function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attack…
    from 0, < 2:1.4.1~git20080517-2
  • CVE-2008-2362Multiple integer overflows in the Render extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitr…
    from 0, < 2:1.4.1~git20080517-2
  • CVE-2008-1377xorg-server - multiple vulnerabilities
    from 0, < 2:1.4.1~git20080517-2
  • CVE-2007-5760xorg-server - multiple vulnerabilities
    from 0, < 2:1.1.1-21etch3
  • CVE-2007-6429Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInf…
    from 0, < 2:1.4.1~git20080105-2
  • CVE-2007-6428The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to re…
    from 0, < 2:1.4.1~git20080105-2
  • CVE-2008-0006Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allo…
    from 0, < 2:1.4.1~git20080105-2
  • CVE-2007-6427The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byt…
    from 0, < 2:1.4.1~git20080105-2
  • CVE-2007-5958X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to th…
    from 0, < 2:1.4.1~git20080105-2
  • CVE-2007-5760xorg-server - multiple vulnerabilities
    from 0, < 2:1.4.1~git20080105-2
  • CVE-2007-5760xorg-server - multiple vulnerabilities
    from 0, < 2:1.3.0.0.dfsg-12lenny2
  • CVE-2007-3920gnome-screensaver - authentication bypass
    from 0, < 2:1.4.1~git20080118-1
  • CVE-2007-4730xorg-server - buffer overflow
    from 0, < 2:1.3.0.0.dfsg-12lenny1
  • CVE-2007-4730xorg-server - buffer overflow
    from 0, < 2:1.4-1
  • CVE-2007-4730xorg-server - buffer overflow
    from 0, < 2:1.1.1-21etch1
  • CVE-2007-2437The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated us…
    from 0, < 2:1.3.0.0.dfsg-4
  • CVE-2007-1003xfree86
    from 0, < 2:1.1.1-21
  • CVE-2006-6101xfree86
    from 0, < 2:1.1.1-15
  • CVE-2006-6103Integer overflow in the ProcDbeSwapBuffers function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows…
    from 0, < 2:1.1.1-15
  • CVE-2006-6102Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allo…
    from 0, < 2:1.1.1-15
  • CVE-2006-4447X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid…
    from 0, < 1:1.0.2-9
  • CVE-2006-1526Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause a denial of service (crash), as…
    from 0, < 1:1.0.2-8
  • CVE-2006-0745X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the…
    from 0, < 1:1.0.2-1