rpm package
opensuse/libXi&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/libXi&distro=openSUSE%20Tumbleweed
Vulnerabilities (10)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-94282 | Med | 5.6 | < 1.8.3-2.1 | 1.8.3-2.1 | Sep 28, 2026 | An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client. | |
| CVE-2026-94281 | Med | 6.5 | < 1.8.3-2.1 | 1.8.3-2.1 | Sep 24, 2026 | An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client. | |
| CVE-2026-93545 | Med | 6.5 | < 1.8.3-2.1 | 1.8.3-2.1 | Sep 24, 2026 | An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client. | |
| CVE-2026-93544 | Med | 6.5 | < 1.8.3-2.1 | 1.8.3-2.1 | Sep 24, 2026 | An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client. | |
| CVE-2026-93543 | Hig | 7.4 | < 1.8.3-2.1 | 1.8.3-2.1 | Sep 24, 2026 | An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client. | |
| CVE-2026-93542 | Med | 6.5 | < 1.8.3-2.1 | 1.8.3-2.1 | Sep 24, 2026 | An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client. | |
| CVE-2026-93541 | Med | 6.5 | < 1.8.3-2.1 | 1.8.3-2.1 | Sep 24, 2026 | An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a | |
| CVE-2013-1998 | — | < 1.7.8-1.1 | 1.7.8-1.1 | Jun 15, 2013 | Multiple buffer overflows in X.org libXi 1.7.1 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XGetDeviceButtonMapping, (2) XIPassiveGrabDevice, and (3) XQueryDeviceState functions. | ||
| CVE-2013-1995 | — | < 1.7.8-1.1 | 1.7.8-1.1 | Jun 15, 2013 | X.org libXi 1.7.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to an unexpected sign extension in the XListInputDevices function. | ||
| CVE-2013-1984 | — | < 1.7.8-1.1 | 1.7.8-1.1 | Jun 15, 2013 | Multiple integer overflows in X.org libXi 1.7.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XGetDeviceControl, (2) XGetFeedbackControl, (3) XGetDeviceDontPropagateList, (4) XGetDeviceMotionEvents, ( |
- affected < 1.8.3-2.1fixed 1.8.3-2.1
An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client.
- affected < 1.8.3-2.1fixed 1.8.3-2.1
An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
- affected < 1.8.3-2.1fixed 1.8.3-2.1
An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
- affected < 1.8.3-2.1fixed 1.8.3-2.1
An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.
- affected < 1.8.3-2.1fixed 1.8.3-2.1
An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
- affected < 1.8.3-2.1fixed 1.8.3-2.1
An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client.
- affected < 1.8.3-2.1fixed 1.8.3-2.1
An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a
- CVE-2013-1998Jun 15, 2013affected < 1.7.8-1.1fixed 1.7.8-1.1
Multiple buffer overflows in X.org libXi 1.7.1 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XGetDeviceButtonMapping, (2) XIPassiveGrabDevice, and (3) XQueryDeviceState functions.
- CVE-2013-1995Jun 15, 2013affected < 1.7.8-1.1fixed 1.7.8-1.1
X.org libXi 1.7.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to an unexpected sign extension in the XListInputDevices function.
- CVE-2013-1984Jun 15, 2013affected < 1.7.8-1.1fixed 1.7.8-1.1
Multiple integer overflows in X.org libXi 1.7.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XGetDeviceControl, (2) XGetFeedbackControl, (3) XGetDeviceDontPropagateList, (4) XGetDeviceMotionEvents, (