rpm package
suse/libX11&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP5
pkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5
Vulnerabilities (7)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-43787 | — | < 1.6.2-12.33.1 | 1.6.2-12.33.1 | Oct 10, 2023 | A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges. | ||
| CVE-2023-43786 | — | < 1.6.2-12.33.1 | 1.6.2-12.33.1 | Oct 10, 2023 | A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition. | ||
| CVE-2023-43785 | — | < 1.6.2-12.33.1 | 1.6.2-12.33.1 | Oct 10, 2023 | A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows a local user to trigger an out-of-bounds read error and read the contents of memory on the system. | ||
| CVE-2023-3138 | — | < 1.6.2-12.30.1 | 1.6.2-12.30.1 | Jun 28, 2023 | A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array in | ||
| CVE-2021-31535 | — | < 1.6.2-12.18.1 | 1.6.2-12.18.1 | May 27, 2021 | LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor request (intended for server-side color lookup) contains a flaw allowing a client to send color-name requests with a name longer than the | ||
| CVE-2020-14363 | — | < 1.6.2-12.15.1 | 1.6.2-12.15.1 | Sep 11, 2020 | An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases, result in arbitrary code execution. The highest threat from this flaw is to confid | ||
| CVE-2020-14344 | — | < 1.6.2-12.8.1 | 1.6.2-12.8.1 | Aug 5, 2020 | An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running with elevated privileges. No |
- CVE-2023-43787Oct 10, 2023affected < 1.6.2-12.33.1fixed 1.6.2-12.33.1
A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges.
- CVE-2023-43786Oct 10, 2023affected < 1.6.2-12.33.1fixed 1.6.2-12.33.1
A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition.
- CVE-2023-43785Oct 10, 2023affected < 1.6.2-12.33.1fixed 1.6.2-12.33.1
A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows a local user to trigger an out-of-bounds read error and read the contents of memory on the system.
- CVE-2023-3138Jun 28, 2023affected < 1.6.2-12.30.1fixed 1.6.2-12.30.1
A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array in
- CVE-2021-31535May 27, 2021affected < 1.6.2-12.18.1fixed 1.6.2-12.18.1
LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor request (intended for server-side color lookup) contains a flaw allowing a client to send color-name requests with a name longer than the
- CVE-2020-14363Sep 11, 2020affected < 1.6.2-12.15.1fixed 1.6.2-12.15.1
An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases, result in arbitrary code execution. The highest threat from this flaw is to confid
- CVE-2020-14344Aug 5, 2020affected < 1.6.2-12.8.1fixed 1.6.2-12.8.1
An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running with elevated privileges. No