Количество 33
Количество 33
BDU:2024-03104
Уязвимость функции ProcXIPassiveGrabDevice() сервера X Window System Xorg-server, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
ALT-PU-2024-5112
ALT-PU-2024-5112: package `xorg-xwayland` update to version 23.1.1-alt5
ROS-20240507-07
Множественные уязвимости xorg-x11-server-common
ALT-PU-2024-5110
ALT-PU-2024-5110: package `xorg-server` update to version 1.20.14-alt12
CVE-2024-31081
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.
CVE-2024-31081
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.
CVE-2024-31081
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.
CVE-2024-31081
CVE-2024-31081
A heap-based buffer over-read vulnerability was found in the X.org ser ...
GHSA-3fpg-j8cw-vcjq
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.
BDU:2024-03109
Уязвимость функции ProcAppleDRICreatePixmap() сервера X Window System Xorg-server, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
SUSE-SU-2024:2776-1
Security update for dri3proto, presentproto, wayland-protocols, xwayland
SUSE-SU-2024:1264-1
Security update for xwayland
RLSA-2024:9122
Moderate: xorg-x11-server security update
RLSA-2024:9093
Moderate: xorg-x11-server-Xwayland security update
RLSA-2024:3343
Important: xorg-x11-server-Xwayland security update
RLSA-2024:3261
Important: tigervnc security update
RLSA-2024:3258
Moderate: xorg-x11-server security update
RLSA-2024:2616
Important: tigervnc security update
RLSA-2024:2037
Important: tigervnc security update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2024-03104 Уязвимость функции ProcXIPassiveGrabDevice() сервера X Window System Xorg-server, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании | CVSS3: 7.3 | 1% Низкий | больше 2 лет назад | |
ALT-PU-2024-5112 ALT-PU-2024-5112: package `xorg-xwayland` update to version 23.1.1-alt5 | CVSS3: 7.8 | больше 2 лет назад | ||
ROS-20240507-07 Множественные уязвимости xorg-x11-server-common | CVSS3: 7.8 | больше 2 лет назад | ||
ALT-PU-2024-5110 ALT-PU-2024-5110: package `xorg-server` update to version 1.20.14-alt12 | CVSS3: 7.8 | больше 2 лет назад | ||
CVE-2024-31081 A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads. | CVSS3: 7.3 | 1% Низкий | больше 2 лет назад | |
CVE-2024-31081 A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads. | CVSS3: 7.3 | 1% Низкий | больше 2 лет назад | |
CVE-2024-31081 A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads. | CVSS3: 7.3 | 1% Низкий | больше 2 лет назад | |
CVSS3: 7.3 | 1% Низкий | около 2 лет назад | ||
CVE-2024-31081 A heap-based buffer over-read vulnerability was found in the X.org ser ... | CVSS3: 7.3 | 1% Низкий | больше 2 лет назад | |
GHSA-3fpg-j8cw-vcjq A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads. | CVSS3: 7.3 | 1% Низкий | больше 2 лет назад | |
BDU:2024-03109 Уязвимость функции ProcAppleDRICreatePixmap() сервера X Window System Xorg-server, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании | CVSS3: 7.3 | 0% Низкий | больше 2 лет назад | |
SUSE-SU-2024:2776-1 Security update for dri3proto, presentproto, wayland-protocols, xwayland | около 2 лет назад | |||
SUSE-SU-2024:1264-1 Security update for xwayland | больше 2 лет назад | |||
RLSA-2024:9122 Moderate: xorg-x11-server security update | больше 1 года назад | |||
RLSA-2024:9093 Moderate: xorg-x11-server-Xwayland security update | больше 1 года назад | |||
RLSA-2024:3343 Important: xorg-x11-server-Xwayland security update | больше 2 лет назад | |||
RLSA-2024:3261 Important: tigervnc security update | больше 2 лет назад | |||
RLSA-2024:3258 Moderate: xorg-x11-server security update | больше 2 лет назад | |||
RLSA-2024:2616 Important: tigervnc security update | больше 2 лет назад | |||
RLSA-2024:2037 Important: tigervnc security update | больше 2 лет назад |
Уязвимостей на страницу