📦 X Server

by X.org

🔍 What is X Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-6816

CRITICAL CVSS 9.8 Jan 18, 2024

This vulnerability in X.Org server allows heap overflow when button mapping exceeds allocated memory space. Attackers could exploit this to execute arbitrary code or crash the system. Affects systems ...

CVE-2025-26599

HIGH CVSS 7.8 Feb 25, 2025

This CVE describes an uninitialized pointer vulnerability in X.Org and Xwayland display servers. When compCheckRedirect() fails to allocate a backing pixmap, compRedirectWindow() returns a BadAlloc er...

CVE-2025-26600

HIGH CVSS 7.8 Feb 25, 2025

A use-after-free vulnerability in X.Org and Xwayland allows attackers to potentially execute arbitrary code or cause denial of service when a device is removed while frozen. This affects systems using...

CVE-2025-26601

HIGH CVSS 7.8 Feb 25, 2025

A use-after-free vulnerability in X.Org and Xwayland allows attackers to potentially execute arbitrary code or cause denial of service. This affects systems using X11 display servers or Wayland compos...

CVE-2025-26594

HIGH CVSS 7.8 Feb 25, 2025

A use-after-free vulnerability in X.Org and Xwayland allows attackers to potentially crash the X server or execute arbitrary code by freeing the root cursor. This affects systems running X.Org Server ...

CVE-2025-26595

HIGH CVSS 7.8 Feb 25, 2025

A stack-based buffer overflow vulnerability in X.Org and Xwayland allows attackers to execute arbitrary code or cause denial of service. This affects systems using X Window System or Wayland with Xway...

CVE-2025-26596

HIGH CVSS 7.8 Feb 25, 2025

A heap buffer overflow vulnerability in X.Org and Xwayland allows attackers to write beyond allocated memory boundaries. This affects systems using X11 display servers or Xwayland for Wayland compatib...

CVE-2025-26597

HIGH CVSS 7.8 Feb 25, 2025

A buffer overflow vulnerability in X.Org and Xwayland allows attackers to execute arbitrary code or cause denial of service by exploiting improper memory handling in keyboard symbol table resizing. Th...

CVE-2025-26598

HIGH CVSS 7.8 Feb 25, 2025

This CVE describes an out-of-bounds write vulnerability in X.Org and Xwayland where the GetBarrierDevice() function incorrectly returns the last element of a device list instead of NULL when no matchi...

CVE-2024-0229

HIGH CVSS 7.8 Feb 9, 2024

This vulnerability in the X.Org server allows out-of-bounds memory access when a frozen device is reattached to a different master device. It can lead to application crashes, local privilege escalatio...

CVE-2024-0409

HIGH CVSS 7.8 Jan 18, 2024

This vulnerability in X.Org server's cursor code allows memory corruption by using incorrect private types in Xephyr and Xwayland, potentially leading to privilege escalation or denial of service. It ...

CVE-2023-6377

HIGH CVSS 7.8 Dec 13, 2023

This vulnerability in xorg-server allows out-of-bounds memory reads and writes when querying or changing XKB button actions, such as switching from touchpad to mouse. It could enable local privilege e...

CVE-2023-5367

HIGH CVSS 7.8 Oct 25, 2023

This CVE-2023-5367 is an out-of-bounds write vulnerability in xorg-x11-server that allows attackers to write beyond allocated heap buffers. It could lead to privilege escalation or denial of service o...

CVE-2023-5574

HIGH CVSS 7.0 Oct 25, 2023

A use-after-free vulnerability in xorg-x11-server-Xvfb allows privilege escalation or denial of service when exploiting a specific legacy multi-screen configuration. This affects systems running Xvfb ...

CVE-2023-0494

HIGH CVSS 7.8 Mar 27, 2023

This CVE-2023-0494 vulnerability in X.Org allows attackers to exploit a dangling pointer in DeepCopyPointerClasses via ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() functions. This can lead to loc...

CVE-2020-25697

HIGH CVSS 7.0 May 26, 2021

This CVE describes a privilege escalation vulnerability in Xorg X11 server where clients can connect without proper authentication. Attackers can impersonate the X server to take control of X applicat...

CVE-2021-3472

HIGH CVSS 7.8 Apr 26, 2021

CVE-2021-3472 is an integer underflow vulnerability in xorg-x11-server that allows local attackers to escalate privileges on affected systems. This flaw enables attackers to gain root access from a st...