<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:28:22.272683+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:6497</id>
    <title>ALSA-2023:6497 — Moderate: libX11 security update</title>
    <updated>2026-10-02T12:28:22.456166+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: libX11, AlmaLinux:9: libX11-common, AlmaLinux:9: libX11-devel, AlmaLinux:9: libX11-xcb</p>
<p>The libX11 packages contain the core X11 protocol client library.</p>
<p>Security Fix(es):</p>
<p>* libX11: InitExt.c can overwrite unintended portions of the Display structure if the extension request leads to a buffer overflow (CVE-2023-3138)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:6497"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03596</id>
    <title>bdu:2023-03596</title>
    <updated>2026-10-02T12:28:22.456238+00:00</updated>
    <content>bdu:2023-03596</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03596"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-3138</id>
    <title>Withdrawn: BELL-CVE-2023-3138 — CVE-2023-3138 does not affect BellSoft software</title>
    <updated>2026-10-02T12:28:22.456256+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-3138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0385</id>
    <title>certfr-2024-avi-0385 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-02T12:28:22.456271+00:00</updated>
    <content>certfr-2024-avi-0385</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0385"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-7065</id>
    <title>EUVD-2026-7065</title>
    <updated>2026-10-02T12:28:22.456286+00:00</updated>
    <content>EUVD-2026-7065</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-7065"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-3138</id>
    <title>fkie_cve-2023-3138</title>
    <updated>2026-10-02T12:28:22.456296+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-3138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-849h-8wj5-xmx8</id>
    <title>GHSA-849h-8wj5-xmx8</title>
    <updated>2026-10-02T12:28:22.456320+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-849h-8wj5-xmx8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-3138</id>
    <title>gsd-2023-3138</title>
    <updated>2026-10-02T12:28:22.456337+00:00</updated>
    <content>gsd-2023-3138</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-3138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-3138</id>
    <title>msrc_CVE-2023-3138 — A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not c…</title>
    <updated>2026-10-02T12:28:22.456347+00:00</updated>
    <content>msrc_CVE-2023-3138</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-3138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1376</id>
    <title>OESA-2023-1376 — libX11 security update</title>
    <updated>2026-10-02T12:28:22.456365+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: libX11</p>
<p>Core X11 protocol client library.</p>
<p>Security Fix(es):</p>
<p>A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.(CVE-2023-3138)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1376"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13008-1</id>
    <title>openSUSE-SU-2024:13008-1 — libX11-6-1.8.5-2.1 on GA media</title>
    <updated>2026-10-02T12:28:22.456390+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libX11-6-1.8.5-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13008-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:1088</id>
    <title>RHSA-2024:1088 — Red Hat Security Advisory: libX11 security update</title>
    <updated>2026-10-02T12:28:22.456407+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libX11: InitExt.c can overwrite unintended portions of the Display structure if the extension request leads to a buffer overflow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:1088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:2531-1</id>
    <title>SUSE-SU-2023:2531-1 — Security update for libX11</title>
    <updated>2026-10-02T12:28:22.456422+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libX11</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:2531-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-3138</id>
    <title>UBUNTU-CVE-2023-3138</title>
    <updated>2026-10-02T12:28:22.456436+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libx11, Ubuntu:Pro:16.04:LTS: libx11, Ubuntu:Pro:18.04:LTS: libx11, Ubuntu:20.04:LTS: libx11, Ubuntu:22.04:LTS: libx11</p>
<p>A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-3138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1485</id>
    <title>WID-SEC-W-2023-1485 — X.Org X11: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T12:28:22.456463+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in X.Org X11 ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1485"/>
  </entry>
</feed>
