Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3040▲ 560 respecto a la semana anterior
Críticas / altas1452▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

199 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.6)0.13%—X.org LibxiAI28/9/202630/9/2026
An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client.
Pendiente de análisisMedia (6.5)0.20%—X.org LibxiAI24/9/202624/9/2026
An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
Pendiente de análisisMedia (6.5)0.20%—X.org LibxiAI24/9/202624/9/2026
An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
Pendiente de análisisMedia (6.5)0.24%—X.org LibxiAI24/9/202624/9/2026
An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.
Pendiente de análisisAlta (7.4)0.25%—X.org LibxiAI24/9/202624/9/2026
An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
Pendiente de análisisMedia (6.5)0.25%—X.org LibxiAI24/9/202624/9/2026
An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client.
Pendiente de análisisMedia (6.5)0.24%—X.org LibxiAI24/9/202624/9/2026
An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a
AnalizadaCrítica (9)0.31%—X.org X ServerX.org Xwayland8/7/20269/7/2026
Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.
AnalizadaAlta (7.8)0.33%—X.org X ServerX.org Xwayland8/7/20269/7/2026
Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
ModificadaAlta (7.8)0.20%—X.org X ServerX.org XwaylandRedhat Enterprise Linux5/6/202627/7/2026
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the…
ModificadaMedia (5.5)0.19%—X.org X ServerX.org XwaylandRedhat Enterprise Linux5/6/20265/8/2026
A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.
ModificadaMedia (5.5)0.18%—X.org X ServerX.org XwaylandRedhat Enterprise Linux5/6/20265/8/2026
An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which…
ModificadaAlta (7.8)0.20%—X.org X ServerX.org XwaylandRedhat Enterprise Linux5/6/20265/8/2026
A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege…
ModificadaAlta (7.8)0.20%—X.org X ServerX.org XwaylandRedhat Enterprise Linux5/6/20265/8/2026
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if…
ModificadaAlta (7.8)0.22%—X.org X ServerX.org XwaylandRedhat Enterprise Linux5/6/20265/8/2026
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to…
ModificadaAlta (7.8)0.22%—X.org X ServerX.org XwaylandRedhat Enterprise Linux5/6/20265/8/2026
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger…
ModificadaAlta (7.8)0.20%—X.org X ServerX.org XwaylandRedhat Enterprise Linux5/6/20265/8/2026
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence,…
ModificadaAlta (7.8)0.21%—X.org X ServerX.org XwaylandRedhat Enterprise Linux5/6/20265/8/2026
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is…
ModificadaCrítica (9.1)0.53%—X.org X ServerRedhat Enterprise Linux5/5/202617/6/2026
A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit this by sending a malformed request, which causes the server to read beyond its intended memory boundaries. This can…
ModificadaCrítica (9.1)0.53%—X.org X ServerRedhat Enterprise Linux5/5/202617/6/2026
A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a connection to the X11 server, either locally or…
Pendiente de análisisAlta (7.8)0.19%—X.org X ServerAI23/4/202615/7/2026
A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, leading to a Denial of…
Pendiente de análisisAlta (7.8)0.19%—X.org X ServerAI23/4/202615/7/2026
A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory…
Pendiente de análisisAlta (7.8)0.19%—X.org X ServerAI23/4/202615/7/2026
A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other…
AnalizadaAlta (7.3)0.28%—X.org X ServerX.org XwaylandIBM ViosIBM AIX+730/10/20251/7/2026
A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.
AplazadaAlta (7.3)0.51%—X.org X ServerAIX.org XwaylandAI30/10/202517/6/2026
A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute…