The XInput extension in X.Org X Window System (aka X11 or X) X11R4 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) SProcXChangeDeviceControl, (2) ProcXChangeDeviceControl, (3) ProcXChangeFeedbackControl, (4) ProcXSendExtensionEvent, (5) SProcXIAllowEvents, (6) SProcXIChangeCursor, (7) ProcXIChangeHierarchy, (8) SProcXIGetClientPointer, (9) SProcXIGrabDevice, (10) SProcXIUngrabDevice, (11) ProcXIUngrabDevice, (12) SProcXIPassiveGrabDevice, (13) ProcXIPassiveGrabDevice, (14) SProcXIPassiveUngrabDevice, (15) ProcXIPassiveUngrabDevice, (16) SProcXListDeviceProperties, (17) SProcXDeleteDeviceProperty, (18) SProcXIListProperties, (19) SProcXIDeleteProperty, (20) SProcXIGetProperty, (21) SProcXIQueryDevice, (22) SProcXIQueryPointer, (23) SProcXISelectEvents, (24) SProcXISetClientPointer, (25) SProcXISetFocus, (26) SProcXIGetFocus, or (27) SProcXIWarpPointer function.
                
            References
                    Configurations
                    History
                    29 Aug 2025, 13:42
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:* | |
| First Time | X.org x Server | 
21 Nov 2024, 02:18
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://advisories.mageia.org/MGASA-2014-0532.html - | |
| References | () http://secunia.com/advisories/61947 - | |
| References | () http://secunia.com/advisories/62292 - | |
| References | () http://www.debian.org/security/2014/dsa-3095 - | |
| References | () http://www.mandriva.com/security/advisories?name=MDVSA-2015:119 - | |
| References | () http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html - | |
| References | () http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html - | |
| References | () http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html - | |
| References | () http://www.securityfocus.com/bid/71599 - | |
| References | () http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/ - Patch, Vendor Advisory | |
| References | () https://security.gentoo.org/glsa/201504-06 - | 
Information
                Published : 2014-12-10 15:59
Updated : 2025-08-29 13:42
NVD link : CVE-2014-8095
Mitre link : CVE-2014-8095
CVE.ORG link : CVE-2014-8095
JSON object : View
Products Affected
                x.org
- x11
- x_server
debian
- debian_linux
CWE
                
                    
                        
                        CWE-119
                        
            Improper Restriction of Operations within the Bounds of a Memory Buffer
