Vulnerabilities
Vulnerable Software
X.org:  >> X Server  >> 1.17.0  Security Vulnerabilities
In the X.Org X server before 2017-06-19, a user authenticated to an X Session could crash or execute code in the context of the X Server by exploiting a stack overflow in the endianness conversion of X Events.
CVSS Score
8.8
EPSS Score
0.02
Published
2017-07-06
Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.
CVSS Score
6.5
EPSS Score
0.006
Published
2017-07-06
The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.
CVSS Score
3.6
EPSS Score
0.001
Published
2015-07-01
X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string length value in a XkbSetGeometry request.
CVSS Score
6.4
EPSS Score
0.082
Published
2015-02-13


Contact Us

Shodan ® - All rights reserved