Search CVE reports
41 – 50 of 134 results
CVE-2020-14347
Low priorityA flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass....
9 affected packages
xorg, xorg-hwe-16.04, xorg-server, xorg-server-hwe-16.04, xorg-server-hwe-18.04...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xorg | — | — | Not affected | Not affected | Not affected |
xorg-hwe-16.04 | — | — | Not in release | Not in release | Not affected |
xorg-server | — | — | Fixed | Fixed | Fixed |
xorg-server-hwe-16.04 | — | — | Not in release | Not in release | Fixed |
xorg-server-hwe-18.04 | — | — | Not in release | Fixed | Not in release |
xorg-server-lts-utopic | — | — | Not in release | Not in release | Not in release |
xorg-server-lts-vivid | — | — | Not in release | Not in release | Not in release |
xorg-server-lts-wily | — | — | Not in release | Not in release | Not in release |
xorg-server-lts-xenial | — | — | Not in release | Not in release | Not in release |
CVE-2012-1093
Low priorityThe init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.
1 affected package
xorg
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xorg | — | Not affected | Not affected | Not affected | Not affected |
CVE-2019-17624
Low priority"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sending ct.c_char 1000 times, an attacker can cause a denial of service (application crash) or possibly...
9 affected packages
xorg, xorg-hwe-16.04, xorg-server, xorg-server-hwe-16.04, xorg-server-hwe-18.04...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xorg | — | — | Not affected | Not affected | Not affected |
xorg-hwe-16.04 | — | — | Not in release | Not in release | Not affected |
xorg-server | — | — | Not affected | Not affected | Not affected |
xorg-server-hwe-16.04 | — | — | Not in release | Not in release | Not affected |
xorg-server-hwe-18.04 | — | — | Not in release | Not affected | Not in release |
xorg-server-lts-utopic | — | — | Not in release | Not in release | Not in release |
xorg-server-lts-vivid | — | — | Not in release | Not in release | Not in release |
xorg-server-lts-wily | — | — | Not in release | Not in release | Not in release |
xorg-server-lts-xenial | — | — | Not in release | Not in release | Not in release |
CVE-2018-3979
Low priorityA remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display driver) handles GPU shader execution. A specially crafted pixel shader can cause remote denial-of-service...
3 affected packages
xserver-xorg-video-nouveau, xserver-xorg-video-nouveau-hwe-16.04, xserver-xorg-video-nouveau-hwe-18.04
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xserver-xorg-video-nouveau | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
xserver-xorg-video-nouveau-hwe-16.04 | Not in release | Not in release | Not in release | Not in release | Vulnerable |
xserver-xorg-video-nouveau-hwe-18.04 | Not in release | Not in release | Not in release | Vulnerable | Not in release |
CVE-2018-14665
Medium priorityA flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical...
8 affected packages
xorg, xorg-hwe-16.04, xorg-server, xorg-server-hwe-16.04, xorg-server-lts-utopic...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xorg | — | — | — | Not affected | Not affected |
xorg-hwe-16.04 | — | — | — | Not in release | Not affected |
xorg-server | — | — | — | Fixed | Not affected |
xorg-server-hwe-16.04 | — | — | — | Not in release | Fixed |
xorg-server-lts-utopic | — | — | — | Not in release | Not in release |
xorg-server-lts-vivid | — | — | — | Not in release | Not in release |
xorg-server-lts-wily | — | — | — | Not in release | Not in release |
xorg-server-lts-xenial | — | — | — | Not in release | Not in release |
CVE-2017-12187
Medium priorityxorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
8 affected packages
xorg, xorg-hwe-16.04, xorg-server, xorg-server-hwe-16.04, xorg-server-lts-utopic...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xorg | — | — | — | — | Not affected |
xorg-hwe-16.04 | — | — | — | — | Not affected |
xorg-server | — | — | — | — | Fixed |
xorg-server-hwe-16.04 | — | — | — | — | Fixed |
xorg-server-lts-utopic | — | — | — | — | Not in release |
xorg-server-lts-vivid | — | — | — | — | Not in release |
xorg-server-lts-wily | — | — | — | — | Not in release |
xorg-server-lts-xenial | — | — | — | — | Not in release |
CVE-2017-12186
Medium priorityxorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
8 affected packages
xorg, xorg-hwe-16.04, xorg-server, xorg-server-hwe-16.04, xorg-server-lts-utopic...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xorg | — | — | — | — | Not affected |
xorg-hwe-16.04 | — | — | — | — | Not affected |
xorg-server | — | — | — | — | Fixed |
xorg-server-hwe-16.04 | — | — | — | — | Fixed |
xorg-server-lts-utopic | — | — | — | — | Not in release |
xorg-server-lts-vivid | — | — | — | — | Not in release |
xorg-server-lts-wily | — | — | — | — | Not in release |
xorg-server-lts-xenial | — | — | — | — | Not in release |
CVE-2017-12185
Medium priorityxorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
8 affected packages
xorg, xorg-hwe-16.04, xorg-server, xorg-server-hwe-16.04, xorg-server-lts-utopic...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xorg | — | — | — | — | Not affected |
xorg-hwe-16.04 | — | — | — | — | Not affected |
xorg-server | — | — | — | — | Fixed |
xorg-server-hwe-16.04 | — | — | — | — | Fixed |
xorg-server-lts-utopic | — | — | — | — | Not in release |
xorg-server-lts-vivid | — | — | — | — | Not in release |
xorg-server-lts-wily | — | — | — | — | Not in release |
xorg-server-lts-xenial | — | — | — | — | Not in release |
CVE-2017-12184
Medium priorityxorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
8 affected packages
xorg, xorg-hwe-16.04, xorg-server, xorg-server-hwe-16.04, xorg-server-lts-utopic...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xorg | — | — | — | — | Not affected |
xorg-hwe-16.04 | — | — | — | — | Not affected |
xorg-server | — | — | — | — | Fixed |
xorg-server-hwe-16.04 | — | — | — | — | Fixed |
xorg-server-lts-utopic | — | — | — | — | Not in release |
xorg-server-lts-vivid | — | — | — | — | Not in release |
xorg-server-lts-wily | — | — | — | — | Not in release |
xorg-server-lts-xenial | — | — | — | — | Not in release |
CVE-2017-12183
Medium priorityxorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
8 affected packages
xorg, xorg-hwe-16.04, xorg-server, xorg-server-hwe-16.04, xorg-server-lts-utopic...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xorg | — | — | — | — | Not affected |
xorg-hwe-16.04 | — | — | — | — | Not affected |
xorg-server | — | — | — | — | Fixed |
xorg-server-hwe-16.04 | — | — | — | — | Fixed |
xorg-server-lts-utopic | — | — | — | — | Not in release |
xorg-server-lts-vivid | — | — | — | — | Not in release |
xorg-server-lts-wily | — | — | — | — | Not in release |
xorg-server-lts-xenial | — | — | — | — | Not in release |