VYPR

rpm package

suse/xorg-x11-server&distro=SUSE Linux Enterprise Point of Sale 11 SP3

pkg:rpm/suse/xorg-x11-server&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3

Vulnerabilities (12)

  • CVE-2021-4011Dec 17, 2021
    affected < 7.4-27.122.46.1fixed 7.4-27.122.46.1

    A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2021-4008Dec 17, 2021
    affected < 7.4-27.122.43.1fixed 7.4-27.122.43.1

    A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2021-3472Apr 26, 2021
    affected < 7.4-27.122.40.1fixed 7.4-27.122.40.1

    A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead to a local privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2020-14360Jan 20, 2021
    affected < 7.4-27.122.37.1fixed 7.4-27.122.37.1

    A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2020-25712Dec 15, 2020
    affected < 7.4-27.122.37.1fixed 7.4-27.122.37.1

    A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2020-14345Sep 15, 2020
    affected < 7.4-27.122.26.1fixed 7.4-27.122.26.1

    A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2020-14362Sep 15, 2020
    affected < 7.4-27.122.29.1fixed 7.4-27.122.29.1

    A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availabilit

  • CVE-2020-14361Sep 15, 2020
    affected < 7.4-27.122.29.1fixed 7.4-27.122.29.1

    A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availabilit

  • CVE-2020-14347Aug 5, 2020
    affected < 7.4-27.122.26.1fixed 7.4-27.122.26.1

    A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.

  • CVE-2018-14665Oct 25, 2018
    affected < 7.4-27.122.21.1fixed 7.4-27.122.21.1

    A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrar

  • CVE-2017-10972MedJul 6, 2017
    affected < 7.4-27.121.2fixed 7.4-27.121.2

    Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.

  • CVE-2017-10971HigJul 6, 2017
    affected < 7.4-27.121.2fixed 7.4-27.121.2

    In the X.Org X server before 2017-06-19, a user authenticated to an X Session could crash or execute code in the context of the X Server by exploiting a stack overflow in the endianness conversion of X Events.