Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

199 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.6%—X.org X ServerX.org XwaylandRedhat Enterprise Linux EUSDebian Linux+113/12/202323/6/2026
A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.
ModificadaAlta (7.8)1.6%—Redhat Enterprise Linux EUSDebian LinuxX.org X ServerX.org Xwayland+113/12/202323/6/2026
A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.
ModificadaAlta (7)0.62%—X.org X ServerRedhat Enterprise Linux25/10/202323/6/2026
A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during…
ModificadaMedia (4.7)0.71%—X.org X ServerX.org XwaylandRedhat Enterprise LinuxFedoraproject Fedora+125/10/202323/6/2026
A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the…
ModificadaAlta (7.8)0.62%—X.org X ServerX.org XwaylandRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+825/10/202323/6/2026
A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation…
ModificadaMedia (5.5)0.38%—X.org LibxpmFedoraproject FedoraRedhat Enterprise Linux10/10/202317/6/2026
A vulnerability was found in libXpm due to a boundary condition within the XpmCreateXpmImageFromBuffer() function. This flaw allows a local attacker to trigger an out-of-bounds read error and read the contents of memory on the system.
ModificadaAlta (7.8)0.47%—X.org Libx11Redhat Enterprise LinuxFedoraproject Fedora10/10/202317/6/2026
A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges.
ModificadaMedia (5.5)0.47%💥 PoCX.org Libx11Redhat Enterprise LinuxFedoraproject Fedora10/10/202317/6/2026
A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition.
ModificadaMedia (5.5)0.67%—X.org Libx11Redhat Enterprise LinuxFedoraproject Fedora10/10/202317/6/2026
A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows a local user to trigger an out-of-bounds read error and read the contents of memory on the system.
ModificadaAlta (7.5)1.7%—X.org Libx11Redhat Enterprise Linux28/6/202317/6/2026
A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called…
ModificadaAlta (7.8)0.44%—X.org X ServerFedoraproject Fedora30/3/202317/6/2026
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.
ModificadaAlta (7.8)0.90%—X.org X ServerFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux AUS+1427/3/202317/6/2026
A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote…
ModificadaAlta (8.8)1.2%—X.org Libxpm7/2/202317/6/2026
A flaw was found in libXpm. When processing files with .Z or .gz extensions, the library calls external programs to compress and uncompress files, relying on the PATH environment variable to find these programs, which could allow a malicious user to execute other programs by manipulating the PATH environment variable.
ModificadaAlta (7.5)1.3%—X.org Libxpm7/2/202317/6/2026
A flaw was found in libXpm. This issue occurs when parsing a file with a comment not closed; the end-of-file condition will not be detected, leading to an infinite loop and resulting in a Denial of Service in the application linked to the library.
ModificadaAlta (7.5)1.2%—X.org Libxpm6/2/202317/6/2026
A flaw was found in libXpm. When processing a file with width of 0 and a very large height, some parser functions will be called repeatedly and can lead to an infinite loop, resulting in a Denial of Service in the application linked to the library.
ModificadaAlta (7.8)1.00%—X.org X ServerFedoraproject FedoraRedhat Enterprise LinuxDebian Linux14/12/202217/6/2026
A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.. This issue can lead to local privileges elevation on systems where the X server is running…
ModificadaAlta (8.8)2.8%—X.org X ServerFedoraproject FedoraDebian Linux14/12/202217/6/2026
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclosure. This issue can lead to local privileges elevation on systems where the X server is running…
ModificadaAlta (8.8)2.5%—X.org X ServerFedoraproject FedoraDebian Linux14/12/202217/6/2026
A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding…
ModificadaAlta (8.8)1.4%—X.org X ServerFedoraproject FedoraDebian Linux14/12/202217/6/2026
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se
ModificadaAlta (8.8)2.6%—X.org X ServerFedoraproject FedoraDebian Linux14/12/202217/6/2026
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveUngrab request accesses out-of-bounds memory when invoked with a high keycode or button code. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code…
ModificadaAlta (8.8)2.6%—X.org X ServerFedoraproject FedoraDebian Linux14/12/202217/6/2026
A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of the XTest extension may corrupt the stack if GenericEvents with lengths larger than 32 bytes are sent through a the XTestFakeInput request. This issue can lead to local privileges elevation on…
ModificadaMedia (6.5)1.3%—X.org X Server17/10/202217/6/2026
A vulnerability, which was classified as problematic, was found in X.org Server. This affects an unknown part of the file hw/xquartz/X11Controller.m of the component xquartz. The manipulation leads to denial of service. It is recommended to apply a patch to fix this issue. The identifier VDB-211053 was assigned to…
ModificadaMedia (6.5)1.9%—X.org X ServerDebian LinuxFedoraproject Fedora17/10/202217/6/2026
A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by this issue is the function ProcXkbGetKbdByName of the file xkb/xkb.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211052.
ModificadaAlta (8.8)1.6%—X.org X ServerDebian LinuxFedoraproject Fedora17/10/202217/6/2026
A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.
ModificadaAlta (7.8)0.63%—X.org X Server1/9/202217/6/2026
A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate…
Orbitaley — Vulnerabilidades