<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:50:10 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:1917 — Moderate: xorg-x11-server and xorg-x11-server-Xwayland security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:1917</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: xorg-x11-server-Xdmx, AlmaLinux:8: xorg-x11-server-Xephyr, AlmaLinux:8: xorg-x11-server-Xnest, AlmaLinux:8: xorg-x11-server-Xorg, AlmaLinux:8: xorg-x11-server-Xvfb, AlmaLinux:8: xorg-x11-server-Xwayland, AlmaLinux:8: xorg-x11-server-common, AlmaLinux:8: xorg-x11-server-devel, AlmaLinux:8: xorg-x11-server-source&lt;/p&gt;
&lt;p&gt;X.Org is an open-source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon.
Xwayland is an X server for running X clients under Wayland.
The following packages have been upgraded to a later upstream version: xorg-x11-server-Xwayland (21.1.3). (BZ#2015842)
Security Fix(es):
* xorg-x11-server: SProcRenderCompositeGlyphs out-of-bounds access (CVE-2021-4008)
* xorg-x11-server: SProcXFixesCreatePointerBarrier out-of-bounds access (CVE-2021-4009)
* xorg-x11-server: SProcScreenSaverSuspend out-of-bounds access (CVE-2021-4010)
* xorg-x11-server: SwapCreateRegister out-of-bounds access (CVE-2021-4011)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: xorg-x11-server-Xdmx, AlmaLinux:8: xorg-x11-server-Xephyr, AlmaLinux:8: xorg-x11-server-Xnest, AlmaLinux:8: xorg-x11-server-Xorg, AlmaLinux:8: xorg-x11-server-Xvfb, AlmaLinux:8: xorg-x11-server-Xwayland, AlmaLinux:8: xorg-x11-server-common, AlmaLinux:8: xorg-x11-server-devel, AlmaLinux:8: xorg-x11-server-source&lt;/p&gt;
&lt;p&gt;X.Org is an open-source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon.
Xwayland is an X server for running X clients under Wayland.
The following packages have been upgraded to a later upstream version: xorg-x11-server-Xwayland (21.1.3). (BZ#2015842)
Security Fix(es):
* xorg-x11-server: SProcRenderCompositeGlyphs out-of-bounds access (CVE-2021-4008)
* xorg-x11-server: SProcXFixesCreatePointerBarrier out-of-bounds access (CVE-2021-4009)
* xorg-x11-server: SProcScreenSaverSuspend out-of-bounds access (CVE-2021-4010)
* xorg-x11-server: SwapCreateRegister out-of-bounds access (CVE-2021-4011)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:1917</guid>
    </item>
    <item>
      <title>bdu:2022-00349</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00349</link>
      <description>bdu:2022-00349</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00349</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-4011 — CVE-2021-4011 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-4011</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-4011</guid>
    </item>
    <item>
      <title>cnvd-2022-04966</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-04966</link>
      <description>cnvd-2022-04966</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-04966</guid>
    </item>
    <item>
      <title>EUVD-2026-21261</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-21261</link>
      <description>EUVD-2026-21261</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-21261</guid>
    </item>
    <item>
      <title>fkie_cve-2021-4011</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-4011</link>
      <description>&lt;p&gt;A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-4011</guid>
    </item>
    <item>
      <title>GHSA-pxmq-rrfv-xh8v</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pxmq-rrfv-xh8v</link>
      <description>&lt;p&gt;A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pxmq-rrfv-xh8v</guid>
    </item>
    <item>
      <title>gsd-2021-4011</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-4011</link>
      <description>gsd-2021-4011</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-4011</guid>
    </item>
    <item>
      <title>OESA-2021-1468 — xorg-x11-server security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1468</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: xorg-x11-server, openEuler:20.03-LTS-SP2: xorg-x11-server&lt;/p&gt;
&lt;p&gt;Xorg server common files.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A security issue has been found in X.Org before version 21.1.2 and Xwayland before version 21.1.4. The handler for the CompositeGlyphs request of the Render extension does not properly validate the request length leading to out of bounds memory write. This can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for SSH X forwarding sessions.(CVE-2021-4008)&#13;
&#13;
A security issue has been found in X.Org before version 21.1.2 and Xwayland before version 21.1.4. The handler for the CreatePointerBarrier request of the XFixes extension does not properly validate the request length leading to out of bounds memory write. This can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for SSH X forwarding sessions.(CVE-2021-4009)&#13;
&#13;
A security issue has been found in X.Org before version 21.1.2 and Xwayland before version 21.1.4. The handler for the Suspend request of the Screen Saver extension does not properly validate the request length leading to an out of bounds memory write. This can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for SSH X forwarding sessions.(CVE-2021-4010)&#13;
&#13;
A security issue has been found in X.Org before version 21.1.2 and Xwayland before version 21.1.4. The handlers for the RecordCreateContext and RecordRegisterClients requests…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: xorg-x11-server, openEuler:20.03-LTS-SP2: xorg-x11-server&lt;/p&gt;
&lt;p&gt;Xorg server common files.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A security issue has been found in X.Org before version 21.1.2 and Xwayland before version 21.1.4. The handler for the CompositeGlyphs request of the Render extension does not properly validate the request length leading to out of bounds memory write. This can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for SSH X forwarding sessions.(CVE-2021-4008)&#13;
&#13;
A security issue has been found in X.Org before version 21.1.2 and Xwayland before version 21.1.4. The handler for the CreatePointerBarrier request of the XFixes extension does not properly validate the request length leading to out of bounds memory write. This can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for SSH X forwarding sessions.(CVE-2021-4009)&#13;
&#13;
A security issue has been found in X.Org before version 21.1.2 and Xwayland before version 21.1.4. The handler for the Suspend request of the Screen Saver extension does not properly validate the request length leading to an out of bounds memory write. This can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for SSH X forwarding sessions.(CVE-2021-4010)&#13;
&#13;
A security issue has been found in X.Org before version 21.1.2 and Xwayland before version 21.1.4. The handlers for the RecordCreateContext and RecordRegisterClients requests…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1468</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:1606-1 — Security update for xorg-x11-server</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1606-1</link>
      <description>&lt;p&gt;Security update for xorg-x11-server&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for xorg-x11-server&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:1606-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:14867-1 — Security update for xorg-x11-server</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:14867-1</link>
      <description>&lt;p&gt;Security update for xorg-x11-server&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for xorg-x11-server&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:14867-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-4011</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-4011</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: xorg-server, Ubuntu:Pro:16.04:LTS: xorg-server, Ubuntu:Pro:16.04:LTS: xorg-server-hwe-16.04, Ubuntu:18.04:LTS: xorg-server, Ubuntu:18.04:LTS: xorg-server-hwe-18.04, Ubuntu:20.04:LTS: xorg-server, Ubuntu:22.04:LTS: xorg-server, Ubuntu:22.04:LTS: xwayland&lt;/p&gt;
&lt;p&gt;A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: xorg-server, Ubuntu:Pro:16.04:LTS: xorg-server, Ubuntu:Pro:16.04:LTS: xorg-server-hwe-16.04, Ubuntu:18.04:LTS: xorg-server, Ubuntu:18.04:LTS: xorg-server-hwe-18.04, Ubuntu:20.04:LTS: xorg-server, Ubuntu:22.04:LTS: xorg-server, Ubuntu:22.04:LTS: xwayland&lt;/p&gt;
&lt;p&gt;A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-4011</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0302 — Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit Administrator…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</guid>
    </item>
  </channel>
</rss>
