VYPR

rpm package

suse/xorg-x11-server&distro=SUSE Linux Enterprise Module for Development Tools 15 SP4

pkg:rpm/suse/xorg-x11-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP4

Vulnerabilities (17)

  • CVE-2023-6478Dec 13, 2023
    affected < 1.20.3-150400.38.32.1fixed 1.20.3-150400.38.32.1

    A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.

  • CVE-2023-6377Dec 13, 2023
    affected < 1.20.3-150400.38.32.1fixed 1.20.3-150400.38.32.1

    A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is inv

  • CVE-2023-5574Oct 25, 2023
    affected < 1.20.3-150400.38.29.1fixed 1.20.3-150400.38.29.1

    A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-f

  • CVE-2023-5380Oct 25, 2023
    affected < 1.20.3-150400.38.29.1fixed 1.20.3-150400.38.29.1

    A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root

  • CVE-2023-5367Oct 25, 2023
    affected < 1.20.3-150400.38.29.1fixed 1.20.3-150400.38.29.1

    A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrprope

  • CVE-2023-1393Mar 30, 2023
    affected < 1.20.3-150400.38.22.1fixed 1.20.3-150400.38.22.1

    A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will tri

  • CVE-2023-0494Mar 27, 2023
    affected < 1.20.3-150400.38.16.1fixed 1.20.3-150400.38.16.1

    A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where th

  • CVE-2022-46344Dec 14, 2022
    affected < 1.20.3-150400.38.13.1fixed 1.20.3-150400.38.13.1

    A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclosure. This issue can lead to local privileges elevation on sy

  • CVE-2022-46343Dec 14, 2022
    affected < 1.20.3-150400.38.13.1fixed 1.20.3-150400.38.13.1

    A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote

  • CVE-2022-46342Dec 14, 2022
    affected < 1.20.3-150400.38.13.1fixed 1.20.3-150400.38.13.1

    A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se

  • CVE-2022-46341Dec 14, 2022
    affected < 1.20.3-150400.38.13.1fixed 1.20.3-150400.38.13.1

    A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveUngrab request accesses out-of-bounds memory when invoked with a high keycode or button code. This issue can lead to local privileges elevation on systems where the X server is runn

  • CVE-2022-46340Dec 14, 2022
    affected < 1.20.3-150400.38.13.1fixed 1.20.3-150400.38.13.1

    A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of the XTest extension may corrupt the stack if GenericEvents with lengths larger than 32 bytes are sent through a the XTestFakeInput request. This issue can lead

  • CVE-2022-4283Dec 14, 2022
    affected < 1.20.3-150400.38.13.1fixed 1.20.3-150400.38.13.1

    A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.. This issue can lead to local privileges elevation on systems

  • CVE-2022-3551Oct 17, 2022
    affected < 1.20.3-150400.38.8.1fixed 1.20.3-150400.38.8.1

    A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by this issue is the function ProcXkbGetKbdByName of the file xkb/xkb.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of t

  • CVE-2022-3550Oct 17, 2022
    affected < 1.20.3-150400.38.8.1fixed 1.20.3-150400.38.8.1

    A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of

  • CVE-2022-2320Sep 1, 2022
    affected < 1.20.3-150400.38.5.1fixed 1.20.3-150400.38.5.1

    A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw a

  • CVE-2022-2319Sep 1, 2022
    affected < 1.20.3-150400.38.5.1fixed 1.20.3-150400.38.5.1

    A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur in the ProcXkbSetGeometry function due to improper validation of the request length.