Vulnerability Name:

CVE-2007-6427 (CCN-39759)

Assigned:2007-12-18
Published:2008-01-17
Updated:2020-11-20
Summary:The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.
CVSS v3 Severity:9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.6 High (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-787
Vulnerability Consequences:Gain Privileges
References:Source: CCN
Type: IBM SECURITY ADVISORY
Multiple vulnerabilities in the X server

Source: CONFIRM
Type: Issue Tracking, Patch, Third Party Advisory
http://bugs.gentoo.org/show_bug.cgi?id=204362

Source: MITRE
Type: CNA
CVE-2007-6427

Source: CCN
Type: Apple Web site
About Security Update 2008-002

Source: CONFIRM
Type: Broken Link
http://docs.info.apple.com/article.html?artnum=307562

Source: CCN
Type: HP Security Bulletin HPSBUX02381 SSRT080083 rev.1
HP-UX Running Xserver, Remote Execution of Arbitrary Code

Source: HP
Type: Broken Link
SSRT080083

Source: IDEFENSE
Type: Broken Link
20080117 Multiple Vendor X Server XInput Extension Multiple Memory Corruption Vulnerabilities

Source: APPLE
Type: Mailing List
APPLE-SA-2008-03-18

Source: CCN
Type: X.Org Mailing List, Thu Jan 17 06:05:34 PST 2008
X.Org security advisory: multiple vulnerabilities in the X server

Source: MLIST
Type: Third Party Advisory
[xorg] 20080117 X.Org security advisory: multiple vulnerabilities in the X server

Source: SUSE
Type: Mailing List, Third Party Advisory
SUSE-SA:2008:003

Source: SUSE
Type: Mailing List, Third Party Advisory
SUSE-SR:2008:003

Source: SUSE
Type: Mailing List, Third Party Advisory
SUSE-SR:2008:008

Source: CCN
Type: RHSA-2008-0029
Important: XFree86 security update

Source: CCN
Type: RHSA-2008-0030
Important: xorg-x11 security update

Source: CCN
Type: RHSA-2008-0031
Important: xorg-x11-server security update

Source: SECUNIA
Type: Third Party Advisory
28273

Source: CCN
Type: SA28532
X.org X11 Multiple Vulnerabilities

Source: SECUNIA
Type: Third Party Advisory
28532

Source: SECUNIA
Type: Third Party Advisory
28535

Source: SECUNIA
Type: Third Party Advisory
28536

Source: SECUNIA
Type: Third Party Advisory
28539

Source: SECUNIA
Type: Third Party Advisory
28540

Source: SECUNIA
Type: Third Party Advisory
28542

Source: SECUNIA
Type: Third Party Advisory
28543

Source: CCN
Type: SA28550
Sun Solaris X Window System and X Server Multiple Vulnerabilities

Source: SECUNIA
Type: Third Party Advisory
28550

Source: SECUNIA
Type: Third Party Advisory
28584

Source: SECUNIA
Type: Third Party Advisory
28592

Source: SECUNIA
Type: Third Party Advisory
28616

Source: CCN
Type: SA28693
Avaya CMS Solaris X Window System and X Server Multiple Vulnerabilities

Source: SECUNIA
Type: Third Party Advisory
28693

Source: SECUNIA
Type: Third Party Advisory
28718

Source: SECUNIA
Type: Third Party Advisory
28838

Source: SECUNIA
Type: Third Party Advisory
28843

Source: CCN
Type: SA28885
NX Server X11 Multiple Vulnerabilities

Source: SECUNIA
Type: Third Party Advisory
28885

Source: CCN
Type: SA28941
Avaya CMS Sun Solaris X Window System and X Server Vulnerabilities

Source: SECUNIA
Type: Third Party Advisory
28941

Source: CCN
Type: SA29139
IBM AIX X Server Multiple Vulnerabilities

Source: SECUNIA
Type: Third Party Advisory
29139

Source: CCN
Type: SA29420
Mac OS X Security Update Fixes Multiple Vulnerabilities

Source: SECUNIA
Type: Third Party Advisory
29420

Source: SECUNIA
Type: Third Party Advisory
29622

Source: SECUNIA
Type: Third Party Advisory
29707

Source: CCN
Type: SA30161
Gentoo ltsp Multiple Vulnerabilities

Source: SECUNIA
Type: Third Party Advisory
30161

Source: CCN
Type: SA32545
HP-UX Xserver Multiple Vulnerabilities

Source: SECUNIA
Type: Third Party Advisory
32545

Source: CCN
Type: SA47270
IBM AIX X Server Two Vulnerabilities

Source: GENTOO
Type: Third Party Advisory
GLSA-200801-09

Source: GENTOO
Type: Third Party Advisory
GLSA-200804-05

Source: CCN
Type: SECTRACK ID: 1019232
X Server Bugs in XFree86, Xinput, TOG-CUP, MIT-SHM, and EVI Extensions Let Local Users Gain Root Privileges

Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1019232

Source: CCN
Type: Sun Alert ID: 103200
Multiple Security Vulnerabilities in the Solaris X Server Extensions May Lead to a Denial of Service (DoS) Condition or Allow Execution of Arbitrary Code

Source: SUNALERT
Type: Broken Link
103200

Source: SUNALERT
Type: Broken Link
200153

Source: CCN
Type: ASA-2008-035
XFree86 security update (RHSA-2008-0029)

Source: CCN
Type: ASA-2008-036
xorg-x11 security update (RHSA-2008-0030)

Source: CONFIRM
Type: Third Party Advisory
http://support.avaya.com/elmodocs2/security/ASA-2008-039.htm

Source: CCN
Type: ASA-2008-039
Multiple Security Vulnerabilities in the Solaris X Server Extensions May Lead to a Denial of Service (DoS) Condition or Allow Execution of Arbitrary Code

Source: CCN
Type: ASA-2008-077
A Security Vulnerability in the Solaris X Window System (X(5)) PCF Font Handler May Lead to Execution of Arbitrary Code or a Denial of Service (DoS) Condition

Source: CCN
Type: ASA-2008-078
Multiple Security Vulnerabilities in the Solaris X Server Extensions May Lead to a Denial of Service (DoS) Condition or Allow Execution of Arbitrary Code

Source: CONFIRM
Type: Third Party Advisory
http://support.avaya.com/elmodocs2/security/ASA-2008-078.htm

Source: CCN
Type: ASA-2008-078
Multiple Security Vulnerabilities in the Solaris X Server Extensions May Lead to a Denial of Service (DoS) Condition or Allow Execution of Arbitrary Code (Sun 200153)

Source: CCN
Type: ASA-2008-431
HPSBUX02381 SSRT080083 rev.1 - HP-UX Running Xserver Remote Execution of Arbitrary Code

Source: DEBIAN
Type: Third Party Advisory
DSA-1466

Source: DEBIAN
Type: DSA-1466
xorg-server -- several vulnerabilities

Source: CCN
Type: GLSA-200801-09
X.Org X server and Xfont library: Multiple vulnerabilities

Source: CCN
Type: GLSA-200805-07
Linux Terminal Server Project: Multiple vulnerabilities

Source: GENTOO
Type: Third Party Advisory
GLSA-200805-07

Source: MANDRIVA
Type: Third Party Advisory
MDVSA-2008:021

Source: MANDRIVA
Type: Third Party Advisory
MDVSA-2008:022

Source: MANDRIVA
Type: Third Party Advisory
MDVSA-2008:023

Source: MANDRIVA
Type: Third Party Advisory
MDVSA-2008:025

Source: OPENBSD
Type: Third Party Advisory
[4.1] 20080208 012: SECURITY FIX: February 8, 2008

Source: OPENBSD
Type: Third Party Advisory
[4.2] 20080208 006: SECURITY FIX: February 8, 2008

Source: REDHAT
Type: Third Party Advisory
RHSA-2008:0029

Source: REDHAT
Type: Third Party Advisory
RHSA-2008:0030

Source: REDHAT
Type: Third Party Advisory
RHSA-2008:0031

Source: BUGTRAQ
Type: Third Party Advisory, VDB Entry
20080130 rPSA-2008-0032-1 xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs

Source: BID
Type: Patch, Third Party Advisory, VDB Entry
27336

Source: CCN
Type: BID-27336
RETIRED: X.Org X Server Local Privilege Escalation and Information Disclosure Vulnerabilities

Source: BID
Type: Third Party Advisory, VDB Entry
27351

Source: CCN
Type: BID-27351
X.Org X Server 'Xinput' Extension Local Privilege Escalation Vulnerability

Source: CCN
Type: USN-571-1
X.org vulnerabilities

Source: CCN
Type: USN-571-2
X.org regression

Source: VUPEN
Type: Third Party Advisory
ADV-2008-0179

Source: VUPEN
Type: Third Party Advisory
ADV-2008-0184

Source: VUPEN
Type: Third Party Advisory
ADV-2008-0497

Source: VUPEN
Type: Third Party Advisory
ADV-2008-0703

Source: VUPEN
Type: Third Party Advisory
ADV-2008-0924

Source: VUPEN
Type: Third Party Advisory
ADV-2008-3000

Source: CCN
Type: IBM Subscription service Bulletin 4136
AIX X server multiple vulnerabilities

Source: CONFIRM
Type: Mitigation, Third Party Advisory
http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX61&path=/200802/SECURITY/20080227/datafile112539&label=AIX%20X%20server%20multiple%20vulnerabilities

Source: CCN
Type: X.Org Foundation Web site
X.Org Wiki - Home

Source: XF
Type: Third Party Advisory, VDB Entry
xorg-xinput-code-execution(39759)

Source: XF
Type: UNKNOWN
xorg-xinput-code-execution(39759)

Source: CONFIRM
Type: Broken Link
https://issues.rpath.com/browse/RPL-2010

Source: CCN
Type: iDefense PUBLIC ADVISORY: 01.17.08
Multiple Vendor X Server XInput Extension Multiple Memory Corruption Vulnerabilities

Source: OVAL
Type: Third Party Advisory
oval:org.mitre.oval:def:10372

Source: UBUNTU
Type: Third Party Advisory
USN-571-1

Source: FEDORA
Type: Third Party Advisory
FEDORA-2008-0760

Source: FEDORA
Type: Third Party Advisory
FEDORA-2008-0831

Source: SUSE
Type: SUSE-SA:2008:003
Xorg Security Problems

Source: SUSE
Type: SUSE-SR:2008:003
SUSE Security Summary Report

Source: SUSE
Type: SUSE-SR:2008:008
SUSE Security Summary Advisory

Vulnerable Configuration:Configuration 1:
  • cpe:/a:x.org:x_server:*:*:*:*:*:*:*:* (Version < 1.4.1)

  • Configuration 2:
  • cpe:/o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:debian:debian_linux:3.1:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:apple:mac_os_x:*:*:*:*:*:*:*:* (Version < 10.4.11)
  • OR cpe:/o:apple:mac_os_x:*:*:*:*:*:*:*:* (Version >= 10.5.0 and < 10.5.2)

  • Configuration 5:
  • cpe:/o:fedoraproject:fedora:7:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:8:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:opensuse:opensuse:10.2:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:10.3:*:*:*:*:*:*:*
  • OR cpe:/o:suse:linux:10.1:*:*:*:*:*:*:*
  • OR cpe:/o:suse:linux_enterprise_desktop:9:*:*:*:*:*:*:*
  • OR cpe:/o:suse:linux_enterprise_desktop:10:-:*:*:*:*:*:*
  • OR cpe:/o:suse:linux_enterprise_desktop:10:sp1:*:*:*:*:*:*
  • OR cpe:/o:suse:linux_enterprise_server:8:*:*:*:*:*:*:*
  • OR cpe:/o:suse:linux_enterprise_server:9:*:*:*:*:*:*:*
  • OR cpe:/o:suse:linux_enterprise_server:10:sp1:*:*:*:*:*:*
  • OR cpe:/o:suse:linux_enterprise_software_development_kit:10:sp1:*:*:*:*:*:*
  • OR cpe:/o:suse:open_enterprise_server:-:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*

  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*

  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:*

  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:5::client_workstation:*:*:*:*:*

  • Configuration RedHat 9:
  • cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:x:x.org_x11:7.3:*:*:*:*:*:*:*
  • AND
  • cpe:/o:sun:solaris:8::x86:*:*:*:*:*
  • OR cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:aix:5.2:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:ws:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:hp:hp-ux:b.11.11:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::ws:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::as:*:*:*:*:*
  • OR cpe:/o:ibm:aix:6.1:*:*:*:*:*:*:*
  • OR cpe:/o:sun:solaris:8::sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9::x86:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::desktop:*:*:*:*:*
  • OR cpe:/o:ibm:aix:5.3:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*
  • OR cpe:/o:novell:linux_desktop:9:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.1:*:*:*:*:*:*:*
  • OR cpe:/a:novell:open_enterprise_server:*:*:*:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10::sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10::x86:*:*:*:*:*
  • OR cpe:/o:redhat:linux_advanced_workstation:2.1::itanium:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:6.06::lts:*:*:*:*:*
  • OR cpe:/o:novell:suse_linux_enterprise_server:10:sp2:itanium_ia64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:5:*:client_workstation:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007.1:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.0::x86-64:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:7.04:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:5:*:client:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:7.10:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007.1::x86-64:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4.6.z:ga:as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4.6.z:ga:es:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:novell:open_enterprise_server:*:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:10.2:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:10.3:*:*:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9::sparc:*:*:*:*:*
  • OR cpe:/o:ibm:aix:7.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20076427
    V
    CVE-2007-6427
    2022-06-30
    oval:org.opensuse.security:def:113603
    P
    xorg-x11-server-1.20.13-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:26221
    P
    Security update for python-numpy (Moderate) (in QA)
    2022-01-17
    oval:org.opensuse.security:def:26217
    P
    Security update for java-1_7_1-ibm (Moderate) (in QA)
    2022-01-04
    oval:org.opensuse.security:def:42252
    P
    Security update for runc (Moderate)
    2021-12-23
    oval:org.opensuse.security:def:26187
    P
    Security update for libvpx (Moderate)
    2021-12-23
    oval:org.opensuse.security:def:32250
    P
    Security update for log4j (Important)
    2021-12-17
    oval:org.opensuse.security:def:32242
    P
    Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP3) (Important)
    2021-12-14
    oval:org.opensuse.security:def:31324
    P
    Security update for the Linux Kernel (Live Patch 41 for SLE 12 SP3) (Important)
    2021-12-14
    oval:org.opensuse.security:def:31313
    P
    Security update for ruby2.1 (Important)
    2021-12-01
    oval:org.opensuse.security:def:31312
    P
    Security update for java-1_7_0-openjdk (Important)
    2021-11-24
    oval:org.opensuse.security:def:26171
    P
    Security update for postgresql10 (Important)
    2021-11-22
    oval:org.opensuse.security:def:26164
    P
    Security update for MozillaFirefox (Important)
    2021-11-17
    oval:org.opensuse.security:def:26153
    P
    Security update for git (Low)
    2021-10-20
    oval:org.opensuse.security:def:33024
    P
    Security update for util-linux (Moderate)
    2021-10-19
    oval:org.opensuse.security:def:26142
    P
    Security update for apache2 (Important)
    2021-10-06
    oval:org.opensuse.security:def:26141
    P
    Security update for webkit2gtk3 (Important)
    2021-10-06
    oval:org.opensuse.security:def:106987
    P
    xorg-x11-server-1.20.13-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:32193
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-09-23
    oval:org.opensuse.security:def:26127
    P
    Security update for postgresql12 (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:31679
    P
    Security update for xen (Important)
    2021-09-06
    oval:org.opensuse.security:def:26113
    P
    Security update for mysql-connector-java (Moderate)
    2021-08-30
    oval:org.opensuse.security:def:32985
    P
    Security update for openssl (Important)
    2021-08-24
    oval:org.opensuse.security:def:32163
    P
    Security update for MozillaFirefox (Important)
    2021-08-17
    oval:org.opensuse.security:def:32137
    P
    Security update for libsolv (Important)
    2021-06-28
    oval:org.opensuse.security:def:26083
    P
    Security update for zziplib (Moderate)
    2021-06-25
    oval:org.opensuse.security:def:32132
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:31207
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-06-18
    oval:org.opensuse.security:def:26074
    P
    Security update for freeradius-server (Moderate)
    2021-06-11
    oval:org.opensuse.security:def:42737
    P
    xorg-x11-Xvnc-7.4-27.105.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36330
    P
    xorg-x11-Xvnc-7.4-27.105.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36592
    P
    xorg-x11-server-sdk-7.4-27.105.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32106
    P
    Security update for the Linux Kernel (Live Patch 33 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:31622
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:32088
    P
    Security update for bind (Important)
    2021-05-04
    oval:org.opensuse.security:def:31613
    P
    Security update for tomcat (Important)
    2021-04-29
    oval:org.opensuse.security:def:26036
    P
    Security update for MozillaFirefox (Important)
    2021-04-27
    oval:org.opensuse.security:def:42060
    P
    Security update for the Linux Kernel (Important)
    2021-04-16
    oval:org.opensuse.security:def:32066
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:26025
    P
    Security update for openexr (Moderate)
    2021-04-07
    oval:org.opensuse.security:def:32281
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:31745
    P
    Security update for glib2 (Important)
    2021-03-16
    oval:org.opensuse.security:def:31731
    P
    Security update for java-1_7_1-ibm (Important)
    2021-02-18
    oval:org.opensuse.security:def:31339
    P
    Security update for the Linux Kernel (Important)
    2021-02-12
    oval:org.opensuse.security:def:25980
    P
    Security update for MozillaFirefox (Critical)
    2020-12-21
    oval:org.opensuse.security:def:25972
    P
    Security update for postgresql12 (Important)
    2020-12-04
    oval:org.opensuse.security:def:35845
    P
    xorg-x11-Xvnc-7.4-27.60.5 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:36061
    P
    xorg-x11-Xvnc-7.4-27.81.7 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:42468
    P
    xorg-x11-Xvnc-7.4-27.81.7 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35653
    P
    xorg-x11-Xvnc-7.4-27.19.19 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:31796
    P
    Security update for MozillaFirefox, mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:26345
    P
    Security update for libgit2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25781
    P
    Security update for libqt4 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31875
    P
    Security update for dbus-1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26844
    P
    xorg-x11-Xvnc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25395
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:31398
    P
    Security update for perl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27293
    P
    squid3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31808
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26483
    P
    Security update for chromium (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25883
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31941
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:25407
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:26240
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32303
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25880
    P
    Security update for libvirt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32014
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26718
    P
    hplip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25936
    P
    Security update for libreoffice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32618
    P
    xorg-x11-Xvnc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31121
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25599
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31766
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26328
    P
    used on wotan :) (Low)
    2020-12-01
    oval:org.opensuse.security:def:25955
    P
    Security update for gstreamer-0_10-plugins-bad (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26820
    P
    squid on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26618
    P
    nagios-plugins on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31133
    P
    Security update for kvm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25737
    P
    Security update for libpng12 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31978
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:26386
    P
    Security update for kdepim, messagelib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31528
    P
    Security update for ruby (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32406
    P
    Security update for wavpack (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26873
    P
    clamav on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25205
    P
    Security update for ceph (Important)
    2020-12-01
    oval:org.opensuse.security:def:27059
    P
    xorg-x11-Xvnc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25610
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26305
    P
    Security update for python-setuptools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32511
    P
    findutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27555
    P
    rubygem-activemodel-3_2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25280
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31488
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25622
    P
    Security update for wavpack (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31837
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:26509
    P
    Security update for cacti, cacti-spine (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32572
    P
    libvorbis on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25489
    P
    Security update for pam_radius (Important)
    2020-12-01
    oval:org.opensuse.security:def:32809
    P
    xorg-x11-Xvnc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25814
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:31981
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:26597
    P
    libpoppler-glib4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33254
    P
    sendmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25630
    P
    Security update for openssl-1_0_0 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31836
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:26809
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25952
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26655
    P
    xterm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31797
    P
    Recommended update for NetworkManager-kde4 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26426
    P
    Security update for singularity (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25834
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31897
    P
    Security update for MozillaFirefox, mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:25396
    P
    Security update for perl-DBI (Important)
    2020-12-01
    oval:org.opensuse.security:def:31530
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:27328
    P
    xorg-x11-Xvnc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25879
    P
    Security update for pidgin-otr (Important)
    2020-12-01
    oval:org.opensuse.security:def:31882
    P
    Security update for dnsmasq (Important)
    2020-12-01
    oval:org.opensuse.security:def:26567
    P
    java-1_4_2-ibm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25922
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32579
    P
    mozilla-xulrunner190 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25471
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26289
    P
    Security update for sane-backends (Important)
    2020-12-01
    oval:org.opensuse.security:def:32347
    P
    Security update for sqlite3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25891
    P
    Security update for libimobiledevice, usbmuxd (Important)
    2020-12-01
    oval:org.opensuse.security:def:26771
    P
    libvirt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31122
    P
    Security update for kvm
    2020-12-01
    oval:org.opensuse.security:def:25680
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31922
    P
    Security update for ghostscript-library (Important)
    2020-12-01
    oval:org.opensuse.security:def:26342
    P
    Security update for openjpeg2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31527
    P
    Security update for Ruby
    2020-12-01
    oval:org.opensuse.security:def:26859
    P
    acpid on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26653
    P
    xorg-x11-Xvnc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25204
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:25821
    P
    Security update for lhasa (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32027
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:27024
    P
    radvd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31539
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:32462
    P
    Security update for xorg-x11-libXfixes (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26917
    P
    hyper-v on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25216
    P
    Security update for permissions (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31431
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25611
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:26456
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:32550
    P
    libexif on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27590
    P
    xorg-x11-server-sdk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25408
    P
    Security update for sane-backends (Important)
    2020-12-01
    oval:org.opensuse.security:def:31575
    P
    Security update for sudo
    2020-12-01
    oval:org.opensuse.security:def:32770
    P
    perl-Tk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25686
    P
    Security update for wicked (Important)
    2020-12-01
    oval:org.opensuse.security:def:31894
    P
    Security update for fetchmail (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26558
    P
    gnutls on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32616
    P
    xen on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25546
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31787
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25895
    P
    Security update for pcsc-lite (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26611
    P
    mailman on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33293
    P
    xorg-x11-Xvnc on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:19689
    V
    HP-UX Running Xserver, Remote Execution of Arbitrary Code
    2015-04-20
    oval:org.mitre.oval:def:17768
    P
    USN-571-1 -- libxfont, xorg-server vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:17702
    P
    USN-571-2 -- xorg-server regression
    2014-06-30
    oval:org.mitre.oval:def:8106
    P
    DSA-1466 xfree86 -- several vulnerabilities
    2014-06-23
    oval:org.mitre.oval:def:20244
    P
    DSA-1466-2 libxfont xfree86 xorg-server - several vulnerabilities
    2014-06-23
    oval:org.mitre.oval:def:22333
    P
    ELSA-2008:0031: xorg-x11-server security update (Important)
    2014-05-26
    oval:org.mitre.oval:def:20265
    V
    Multiple vulnerabilities in the X server
    2014-01-20
    oval:org.mitre.oval:def:10372
    V
    The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.
    2013-04-29
    oval:com.redhat.rhsa:def:20080029
    P
    RHSA-2008:0029: XFree86 security update (Important)
    2008-03-20
    oval:com.redhat.rhsa:def:20080030
    P
    RHSA-2008:0030: xorg-x11 security update (Important)
    2008-03-20
    oval:com.redhat.rhsa:def:20080031
    P
    RHSA-2008:0031: xorg-x11-server security update (Important)
    2008-03-20
    oval:org.debian:def:1466
    V
    several vulnerabilities
    2008-01-21
    BACK
    x.org x server *
    canonical ubuntu linux 6.06
    canonical ubuntu linux 6.10
    canonical ubuntu linux 7.04
    canonical ubuntu linux 7.10
    debian debian linux 3.1
    debian debian linux 4.0
    apple mac os x *
    apple mac os x *
    fedoraproject fedora 7
    fedoraproject fedora 8
    opensuse opensuse 10.2
    opensuse opensuse 10.3
    suse linux 10.1
    suse linux enterprise desktop 9
    suse linux enterprise desktop 10 -
    suse linux enterprise desktop 10 sp1
    suse linux enterprise server 8
    suse linux enterprise server 9
    suse linux enterprise server 10 sp1
    suse linux enterprise software development kit 10 sp1
    suse open enterprise server -
    x x.org x11 7.3
    sun solaris 8
    gentoo linux *
    ibm aix 5.2
    redhat enterprise linux 2.1
    redhat enterprise linux 2.1
    redhat enterprise linux 2.1
    suse suse linux 9.0
    hp hp-ux b.11.11
    redhat enterprise linux 3
    redhat enterprise linux 3
    redhat enterprise linux 3
    ibm aix 6.1
    sun solaris 8
    sun solaris 9
    redhat enterprise linux 3
    ibm aix 5.3
    mandrakesoft mandrake linux corporate server 3.0
    redhat enterprise linux 4
    redhat enterprise linux 4
    novell linux desktop 9
    redhat enterprise linux 4
    redhat enterprise linux 4
    debian debian linux 3.1
    novell open enterprise server *
    sun solaris 10
    sun solaris 10
    redhat linux advanced workstation 2.1
    canonical ubuntu 6.06
    novell suse linux enterprise server 10 sp2
    mandrakesoft mandrake linux 2007
    mandrakesoft mandrake linux 2007
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 3.0
    redhat enterprise linux 5
    redhat enterprise linux 5
    mandrakesoft mandrake linux 2007.1
    mandrakesoft mandrake linux 2008.0
    debian debian linux 4.0
    canonical ubuntu 7.04
    redhat enterprise linux 5
    canonical ubuntu 7.10
    mandrakesoft mandrake linux 2008.0
    mandrakesoft mandrake linux 2007.1
    redhat enterprise linux 4.6.z ga
    redhat enterprise linux 4.6.z ga
    apple mac os x 10.4.11
    apple mac os x server 10.4.11
    apple mac os x 10.5.2
    apple mac os x server 10.5.2
    novell open enterprise server *
    novell opensuse 10.2
    novell opensuse 10.3
    sun solaris 9
    ibm aix 7.1