rpm package
suse/xorg-x11-server&distro=SUSE Enterprise Storage 7
pkg:rpm/suse/xorg-x11-server&distro=SUSE%20Enterprise%20Storage%207
Vulnerabilities (15)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-1393 | — | < 1.20.3-150200.22.5.72.1 | 1.20.3-150200.22.5.72.1 | Mar 30, 2023 | A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will tri | ||
| CVE-2023-0494 | — | < 1.20.3-150200.22.5.66.1 | 1.20.3-150200.22.5.66.1 | Mar 27, 2023 | A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where th | ||
| CVE-2022-46344 | — | < 1.20.3-150200.22.5.63.1 | 1.20.3-150200.22.5.63.1 | Dec 14, 2022 | A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclosure. This issue can lead to local privileges elevation on sy | ||
| CVE-2022-46343 | — | < 1.20.3-150200.22.5.63.1 | 1.20.3-150200.22.5.63.1 | Dec 14, 2022 | A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote | ||
| CVE-2022-46342 | — | < 1.20.3-150200.22.5.63.1 | 1.20.3-150200.22.5.63.1 | Dec 14, 2022 | A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se | ||
| CVE-2022-46341 | — | < 1.20.3-150200.22.5.63.1 | 1.20.3-150200.22.5.63.1 | Dec 14, 2022 | A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveUngrab request accesses out-of-bounds memory when invoked with a high keycode or button code. This issue can lead to local privileges elevation on systems where the X server is runn | ||
| CVE-2022-46340 | — | < 1.20.3-150200.22.5.63.1 | 1.20.3-150200.22.5.63.1 | Dec 14, 2022 | A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of the XTest extension may corrupt the stack if GenericEvents with lengths larger than 32 bytes are sent through a the XTestFakeInput request. This issue can lead | ||
| CVE-2022-4283 | — | < 1.20.3-150200.22.5.63.1 | 1.20.3-150200.22.5.63.1 | Dec 14, 2022 | A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.. This issue can lead to local privileges elevation on systems | ||
| CVE-2022-3551 | — | < 1.20.3-150200.22.5.58.1 | 1.20.3-150200.22.5.58.1 | Oct 17, 2022 | A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by this issue is the function ProcXkbGetKbdByName of the file xkb/xkb.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of t | ||
| CVE-2022-3550 | — | < 1.20.3-150200.22.5.58.1 | 1.20.3-150200.22.5.58.1 | Oct 17, 2022 | A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of | ||
| CVE-2022-2320 | — | < 1.20.3-150200.22.5.55.1 | 1.20.3-150200.22.5.55.1 | Sep 1, 2022 | A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw a | ||
| CVE-2022-2319 | — | < 1.20.3-150200.22.5.55.1 | 1.20.3-150200.22.5.55.1 | Sep 1, 2022 | A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur in the ProcXkbSetGeometry function due to improper validation of the request length. | ||
| CVE-2021-4011 | — | < 1.20.3-22.5.42.1 | 1.20.3-22.5.42.1 | Dec 17, 2021 | A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | ||
| CVE-2021-4010 | — | < 1.20.3-22.5.42.1 | 1.20.3-22.5.42.1 | Dec 17, 2021 | A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSuspend function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | ||
| CVE-2021-4009 | — | < 1.20.3-22.5.42.1 | 1.20.3-22.5.42.1 | Dec 17, 2021 | A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcXFixesCreatePointerBarrier function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. |
- CVE-2023-1393Mar 30, 2023affected < 1.20.3-150200.22.5.72.1fixed 1.20.3-150200.22.5.72.1
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will tri
- CVE-2023-0494Mar 27, 2023affected < 1.20.3-150200.22.5.66.1fixed 1.20.3-150200.22.5.66.1
A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where th
- CVE-2022-46344Dec 14, 2022affected < 1.20.3-150200.22.5.63.1fixed 1.20.3-150200.22.5.63.1
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclosure. This issue can lead to local privileges elevation on sy
- CVE-2022-46343Dec 14, 2022affected < 1.20.3-150200.22.5.63.1fixed 1.20.3-150200.22.5.63.1
A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote
- CVE-2022-46342Dec 14, 2022affected < 1.20.3-150200.22.5.63.1fixed 1.20.3-150200.22.5.63.1
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se
- CVE-2022-46341Dec 14, 2022affected < 1.20.3-150200.22.5.63.1fixed 1.20.3-150200.22.5.63.1
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveUngrab request accesses out-of-bounds memory when invoked with a high keycode or button code. This issue can lead to local privileges elevation on systems where the X server is runn
- CVE-2022-46340Dec 14, 2022affected < 1.20.3-150200.22.5.63.1fixed 1.20.3-150200.22.5.63.1
A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of the XTest extension may corrupt the stack if GenericEvents with lengths larger than 32 bytes are sent through a the XTestFakeInput request. This issue can lead
- CVE-2022-4283Dec 14, 2022affected < 1.20.3-150200.22.5.63.1fixed 1.20.3-150200.22.5.63.1
A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.. This issue can lead to local privileges elevation on systems
- CVE-2022-3551Oct 17, 2022affected < 1.20.3-150200.22.5.58.1fixed 1.20.3-150200.22.5.58.1
A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by this issue is the function ProcXkbGetKbdByName of the file xkb/xkb.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of t
- CVE-2022-3550Oct 17, 2022affected < 1.20.3-150200.22.5.58.1fixed 1.20.3-150200.22.5.58.1
A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of
- CVE-2022-2320Sep 1, 2022affected < 1.20.3-150200.22.5.55.1fixed 1.20.3-150200.22.5.55.1
A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw a
- CVE-2022-2319Sep 1, 2022affected < 1.20.3-150200.22.5.55.1fixed 1.20.3-150200.22.5.55.1
A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur in the ProcXkbSetGeometry function due to improper validation of the request length.
- CVE-2021-4011Dec 17, 2021affected < 1.20.3-22.5.42.1fixed 1.20.3-22.5.42.1
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- CVE-2021-4010Dec 17, 2021affected < 1.20.3-22.5.42.1fixed 1.20.3-22.5.42.1
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSuspend function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- CVE-2021-4009Dec 17, 2021affected < 1.20.3-22.5.42.1fixed 1.20.3-22.5.42.1
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcXFixesCreatePointerBarrier function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.