Page 2 of 16 results (0.006 seconds)

CVSS: 3.6EPSS: 0%CPEs: 7EXPL: 0

The ProcSetEventMask function in difs/events.c in the xfs font server for X.Org X11R6 through X11R6.6 and XFree86 before 3.3.3 calls the SendErrToClient function with a mask value instead of a pointer, which allows local users to cause a denial of service (memory corruption and crash) or obtain potentially sensitive information from memory via a SetEventMask request that triggers an invalid pointer dereference. La función ProcSetEventMask en DEFI/events.c en el servidor de fuentes xfs para X.Org X11R6.6 y X11R6 hasta XFree86 antes de 3.3.3 llama a la función SendErrToClient con un valor de máscara en lugar de un puntero, lo que permite a usuarios locales provocar una denegación de servicio (corrupción de memoria y caída) u obtener información sensible de la memoria a través de una solicitud SetEventMask que dispara una desreferencia de puntero no válido. • http://invisible-island.net/ansification/ansify-xfs-cve.html http://lists.freedesktop.org/archives/xorg-announce/2012-July/002040.html http://marc.info/?l=bugtraq&m=135765511704334&w=2 http://twitter.com/bsdaemon/status/228958599790071809 https://blogs.oracle.com/sunsecurity/entry/cve_2012_1699_denial_of https://bugzilla.redhat.com/show_bug.cgi?id=842841 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19369 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 4.6EPSS: 0%CPEs: 27EXPL: 0

xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physically proximate attackers to bypass an X screen lock via keyboard combinations that break the input grab. xkeyboard-config anterior a 2.5 en X.Org anterior a 7.6 habilita por defecto ciertas funciones de depuración XKB, lo que permite a atacantes físicamente próximos evadir un bloqueo de pantalla X a través de combinaciones de teclado que interrumpen la captura de entrada . • http://gu1.aeroxteam.fr/2012/01/19/bypass-screensaver-locker-program-xorg-111-and-up http://lists.x.org/archives/xorg-announce/2012-January/001797.html http://lists.x.org/archives/xorg-devel/2012-January/028691.html http://securitytracker.com/id?1026549 http://who-t.blogspot.com/2012/01/xkb-breaking-grabs-cve-2012-0064.html http://www.openwall.com/lists/oss-security/2012/01/19/6 http://www.osvdb.org/78445 http://www.x.org/wiki/Development/Security https://bugz • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 8.5EPSS: 1%CPEs: 1EXPL: 1

The GLX extension in X.Org xserver 1.7.7 allows remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary code via (1) a crafted request that triggers a client swap in glx/glxcmdsswap.c; or (2) a crafted length or (3) a negative value in the screen field in a request to glx/glxcmds.c. La extensión GLX en X.Org xserver v1.7.7 permite a usuarios remotos autenticados provocar una denegación de servicio (caída del servidor) y posiblemente ejecutar código arbitrario a través de (1) una solicitud hecha a mano que dispara un canje cliente en glx/glxcmdsswap.c, o (2) una longitud diseñado o (3) un valor negativo en el campo de pantalla en una solicitud para glx/glxcmds.c. • http://cgit.freedesktop.org/xorg/xserver/commit?id=3f0d3f4d97bce75c1828635c322b6560a45a037f http://cgit.freedesktop.org/xorg/xserver/commit?id=6c69235a9dfc52e4b4e47630ff4bab1a820eb543 http://cgit.freedesktop.org/xorg/xserver/commit?id=ec9c97c6bf70b523bc500bd3adf62176f1bb33a4 http://rhn.redhat.com/errata/RHSA-2011-1359.html http://rhn.redhat.com/errata/RHSA-2011-1360.html http://www.openwall.com/lists/oss-security/2011/09/22/7 http://www.openwall.com/lists/oss-security/2011/09/23/4 http://www.openwall.com/ • CWE-20: Improper Input Validation •

CVSS: 3.6EPSS: 0%CPEs: 4EXPL: 0

The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw." La función ProcRenderAddGlyphs en la extensión Render (render/render.c) en X.Org xserver v1.7.7 y anteriores permite a usuarios locales leer la memoria arbitraria y posiblemente causar una denegación de servicio (caída del servidor) a través de vectores no especificados relacionados con una entrada "input sanitization flaw". • http://aix.software.ibm.com/aix/efixes/security/X_advisory2.asc http://cgit.freedesktop.org/xorg/xserver/commit/render/render.c?id=5725849a1b427cd4a72b84e57f211edb35838718 http://rhn.redhat.com/errata/RHSA-2011-1359.html http://rhn.redhat.com/errata/RHSA-2011-1360.html http://securitytracker.com/id?1026149 http://www.openwall.com/lists/oss-security/2011/09/22/8 http://www.openwall.com/lists/oss-security/2011/09/23/5 https://bugs.freedesktop.org/show_bug.cgi?id=28801 https: • CWE-20: Improper Input Validation •

CVSS: 7.6EPSS: 0%CPEs: 1EXPL: 1

The fbComposite function in fbpict.c in the Render extension in the X server in X.Org X11R7.1 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted request, related to an incorrect macro definition. La función fbComposite en fbpict.c en la extensión Render en el servidor de X en X.Org X11R7.1 permite a los usuarios remotos autenticados causar una denegación de servicio (corrupción de memoria y cuelgue del demonio) o posiblemente ejecutar código arbitrario mediante una petición manipulada, relacionado con una definición de macro incorrecta. • http://cgit.freedesktop.org/xorg/xserver/commit/?id=d2f813f7db http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html http://secunia.com/advisories/39650 http://secunia.com/advisories/39834 http://securitytracker.com/id?1023929 http://www.ubuntu.com/usn/USN-939-1 http://www.vupen.com/english/advisories/2010/1185 https://bugzilla.redhat.com/show_bug.cgi?id=495733 https://bugzilla.redhat.com/show_bug.cgi?id=582601 https://oval.cisecurity.org/repository/sea • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-189: Numeric Errors •