Vulnerabilidades en The X.Org Foundation
11 resultadosAnálisis Vexday
The X.Org Foundation registra 11 vulnerabilidades conhecidas na base Vexday, mas nenhuma sob exploração ativa no momento, com ausência de CVEs críticos (CVSS 9+) e nenhuma descoberta recente nos últimos 90 dias. A fraqueza dominante (CWE-391) aponta para falhas no tratamento de erros, sugerindo um padrão histórico de implementação frágil que requer monitoramento contínuo, ainda que o risco imediato seja baixo.
CVE-2017-12179—xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to EPSS 4.4%CVE-2017-12177—xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X serEPSS 4.4%CVE-2017-12186—xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash oEPSS 4.3%CVE-2017-12182—xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash EPSS 4.2%CVE-2017-12180—xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to craEPSS 4.2%CVE-2017-12181—xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash EPSS 4.2%CVE-2017-12183—xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or poEPSS 4.2%CVE-2017-12184—xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or EPSS 4.2%CVE-2017-12178—xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server tEPSS 4.2%CVE-2017-12176—xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause XEPSS 4.2%CVE-2017-12187—xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or poEPSS 3.3%