rpm package
suse/xorg-x11-server&distro=SUSE Linux Enterprise Point of Sale 11 SP3
pkg:rpm/suse/xorg-x11-server&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3
Vulnerabilities (12)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-4011 | — | < 7.4-27.122.46.1 | 7.4-27.122.46.1 | Dec 17, 2021 | A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | ||
| CVE-2021-4008 | — | < 7.4-27.122.43.1 | 7.4-27.122.43.1 | Dec 17, 2021 | A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | ||
| CVE-2021-3472 | — | < 7.4-27.122.40.1 | 7.4-27.122.40.1 | Apr 26, 2021 | A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead to a local privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | ||
| CVE-2020-14360 | — | < 7.4-27.122.37.1 | 7.4-27.122.37.1 | Jan 20, 2021 | A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | ||
| CVE-2020-25712 | — | < 7.4-27.122.37.1 | 7.4-27.122.37.1 | Dec 15, 2020 | A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | ||
| CVE-2020-14345 | — | < 7.4-27.122.26.1 | 7.4-27.122.26.1 | Sep 15, 2020 | A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | ||
| CVE-2020-14362 | — | < 7.4-27.122.29.1 | 7.4-27.122.29.1 | Sep 15, 2020 | A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availabilit | ||
| CVE-2020-14361 | — | < 7.4-27.122.29.1 | 7.4-27.122.29.1 | Sep 15, 2020 | A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availabilit | ||
| CVE-2020-14347 | — | < 7.4-27.122.26.1 | 7.4-27.122.26.1 | Aug 5, 2020 | A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable. | ||
| CVE-2018-14665 | — | < 7.4-27.122.21.1 | 7.4-27.122.21.1 | Oct 25, 2018 | A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrar | ||
| CVE-2017-10972 | Med | 6.5 | < 7.4-27.121.2 | 7.4-27.121.2 | Jul 6, 2017 | Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server. | |
| CVE-2017-10971 | Hig | 8.8 | < 7.4-27.121.2 | 7.4-27.121.2 | Jul 6, 2017 | In the X.Org X server before 2017-06-19, a user authenticated to an X Session could crash or execute code in the context of the X Server by exploiting a stack overflow in the endianness conversion of X Events. |
- CVE-2021-4011Dec 17, 2021affected < 7.4-27.122.46.1fixed 7.4-27.122.46.1
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- CVE-2021-4008Dec 17, 2021affected < 7.4-27.122.43.1fixed 7.4-27.122.43.1
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- CVE-2021-3472Apr 26, 2021affected < 7.4-27.122.40.1fixed 7.4-27.122.40.1
A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead to a local privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- CVE-2020-14360Jan 20, 2021affected < 7.4-27.122.37.1fixed 7.4-27.122.37.1
A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- CVE-2020-25712Dec 15, 2020affected < 7.4-27.122.37.1fixed 7.4-27.122.37.1
A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- CVE-2020-14345Sep 15, 2020affected < 7.4-27.122.26.1fixed 7.4-27.122.26.1
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- CVE-2020-14362Sep 15, 2020affected < 7.4-27.122.29.1fixed 7.4-27.122.29.1
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availabilit
- CVE-2020-14361Sep 15, 2020affected < 7.4-27.122.29.1fixed 7.4-27.122.29.1
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availabilit
- CVE-2020-14347Aug 5, 2020affected < 7.4-27.122.26.1fixed 7.4-27.122.26.1
A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.
- CVE-2018-14665Oct 25, 2018affected < 7.4-27.122.21.1fixed 7.4-27.122.21.1
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrar
- affected < 7.4-27.121.2fixed 7.4-27.121.2
Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.
- affected < 7.4-27.121.2fixed 7.4-27.121.2
In the X.Org X server before 2017-06-19, a user authenticated to an X Session could crash or execute code in the context of the X Server by exploiting a stack overflow in the endianness conversion of X Events.