CVE-2023-5574High· 7.0▾ TwilightA use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped f…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
0.5% → 0.6%
A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.
x_server >= 1.13.0enterprise_linux = 7.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-5380Medium· 4.7A use-after-free flaw was found in the xorg-x11-server
CVE-2023-5367High· 7.8A out-of-bounds write flaw was found in the xorg-x11-server
CVE-2026-50261High· 7.8A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter()
CVE-2026-50260High· 7.8A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter()
CVE-2026-50257High· 7.8A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence()
CVE-2026-50263Medium· 5.5A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow()