Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3040▲ 560 respecto a la semana anterior
Críticas / altas1452▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
199 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.6) | 0.13% | — | X.org LibxiAI | 28/9/2026 | 30/9/2026 | An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client. | |
| Pendiente de análisis | Media (6.5) | 0.20% | — | X.org LibxiAI | 24/9/2026 | 24/9/2026 | An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client. | |
| Pendiente de análisis | Media (6.5) | 0.20% | — | X.org LibxiAI | 24/9/2026 | 24/9/2026 | An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client. | |
| Pendiente de análisis | Media (6.5) | 0.24% | — | X.org LibxiAI | 24/9/2026 | 24/9/2026 | An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client. | |
| Pendiente de análisis | Alta (7.4) | 0.25% | — | X.org LibxiAI | 24/9/2026 | 24/9/2026 | An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client. | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | X.org LibxiAI | 24/9/2026 | 24/9/2026 | An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client. | |
| Pendiente de análisis | Media (6.5) | 0.24% | — | X.org LibxiAI | 24/9/2026 | 24/9/2026 | An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a | |
| Analizada | Crítica (9) | 0.31% | — | X.org X ServerX.org Xwayland | 8/7/2026 | 9/7/2026 | Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory. | |
| Analizada | Alta (7.8) | 0.33% | — | X.org X ServerX.org Xwayland | 8/7/2026 | 9/7/2026 | Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks. | |
| Modificada | Alta (7.8) | 0.20% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 27/7/2026 | An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the… | |
| Modificada | Media (5.5) | 0.19% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure. | |
| Modificada | Media (5.5) | 0.18% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which… | |
| Modificada | Alta (7.8) | 0.20% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege… | |
| Modificada | Alta (7.8) | 0.20% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if… | |
| Modificada | Alta (7.8) | 0.22% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to… | |
| Modificada | Alta (7.8) | 0.22% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger… | |
| Modificada | Alta (7.8) | 0.20% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence,… | |
| Modificada | Alta (7.8) | 0.21% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is… | |
| Modificada | Crítica (9.1) | 0.53% | — | X.org X ServerRedhat Enterprise Linux | 5/5/2026 | 17/6/2026 | A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit this by sending a malformed request, which causes the server to read beyond its intended memory boundaries. This can… | |
| Modificada | Crítica (9.1) | 0.53% | — | X.org X ServerRedhat Enterprise Linux | 5/5/2026 | 17/6/2026 | A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a connection to the X11 server, either locally or… | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | X.org X ServerAI | 23/4/2026 | 15/7/2026 | A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, leading to a Denial of… | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | X.org X ServerAI | 23/4/2026 | 15/7/2026 | A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory… | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | X.org X ServerAI | 23/4/2026 | 15/7/2026 | A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other… | |
| Analizada | Alta (7.3) | 0.28% | — | X.org X ServerX.org XwaylandIBM ViosIBM AIX+7 | 30/10/2025 | 1/7/2026 | A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect. | |
| Aplazada | Alta (7.3) | 0.51% | — | X.org X ServerAIX.org XwaylandAI | 30/10/2025 | 17/6/2026 | A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute… |