VulnSea

x_server vulnerabilities

CVEs whose affected-version data names the x_server package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

22 CVEsRSS

CVE-2026-50264High· 7.8
3mo ago

An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat

An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds he…

Twilightx.org · x_serverEPSS 0.15%via NVD
CVE-2026-50263Medium· 5.5
3mo ago

A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow()

A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.

Sunlitx.org · x_serverEPSS 0.14%via NVD
CVE-2026-50262Medium· 5.5
3mo ago

An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes()

An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to informa…

Sunlitx.org · x_serverEPSS 0.13%via NVD
CVE-2026-50261High· 7.8
3mo ago

A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter()

A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while chang…

Twilightx.org · x_serverEPSS 0.15%via NVD
CVE-2026-50260High· 7.8
3mo ago

A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter()

A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client…

Twilightx.org · x_serverEPSS 0.15%via NVD
CVE-2026-50259High· 7.8
3mo ago

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at…

Twilightx.org · x_serverEPSS 0.17%via NVD
CVE-2026-50258High· 7.8
3mo ago

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to Xkb…

Twilightx.org · x_serverEPSS 0.16%via NVD
CVE-2026-50257High· 7.8
3mo ago

A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence()

A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to se…

Twilightx.org · x_serverEPSS 0.14%via NVD
CVE-2026-50256High· 7.8
3mo ago

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The ser…

Twilightx.org · x_serverEPSS 0.16%via NVD
CVE-2025-26601High· 7.8
1y ago

A use-after-free flaw was found in X.Org and Xwayland

A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventually, SyncInitTrigger() is called. If one…

Twilighttigervnc · tigervncEPSS 0.39%via NVD
CVE-2025-26600High· 7.8
1y ago

A use-after-free flaw was found in X.Org and Xwayland

A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free.

Twilighttigervnc · tigervncEPSS 0.39%via NVD
CVE-2025-26599High· 7.8
1y ago

An access to an uninitialized pointer flaw was found in X.Org and Xwayland

An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc error without valid…

Twilighttigervnc · tigervncEPSS 0.40%via NVD
CVE-2025-26598High· 7.8
1y ago

An out-of-bounds write flaw was found in X.Org and Xwayland

An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was found. However, the c…

Twilighttigervnc · tigervncEPSS 0.40%via NVD
CVE-2025-26597High· 7.8
1y ago

A buffer overflow flaw was found in X.Org and Xwayland

A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zer…

Twilighttigervnc · tigervncEPSS 0.44%via NVD
CVE-2025-26596High· 7.8
1y ago

A heap overflow flaw was found in X.Org and Xwayland

A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overflow.

Twilighttigervnc · tigervncEPSS 0.44%via NVD
CVE-2025-26595High· 7.8
1y ago

A buffer overflow flaw was found in X.Org and Xwayland

A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buf…

Twilighttigervnc · tigervncEPSS 0.44%via NVD
CVE-2025-26594High· 7.8
1y ago

A use-after-free flaw was found in X.Org and Xwayland

A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed memory and causes a use-after-free.

Twilighttigervnc · tigervncEPSS 0.39%via NVD
CVE-2023-6478High· 7.6
2y ago

A flaw was found in xorg-server

A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.

Twilightx.org · x_serverEPSS 1.6%via NVD
CVE-2023-6377High· 7.8
2y ago

A flaw was found in xorg-server

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code exe…

Twilightx.org · x_serverEPSS 1.6%via NVD
CVE-2023-5574High· 7.0
2y ago

A use-after-free flaw was found in xorg-x11-server-Xvfb

A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped f…

Twilightx.org · x_serverEPSS 0.62%via NVD
CVE-2023-5380Medium· 4.7
2y ago

A use-after-free flaw was found in the xorg-x11-server

A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped fro…

Sunlitx.org · x_serverEPSS 0.71%via NVD
CVE-2023-5367High· 7.8
2y ago

A out-of-bounds write flaw was found in the xorg-x11-server

A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRCha…

Twilightx.org · x_serverEPSS 0.62%via NVD
x_server vulnerabilities (CVEs) · VulnSea