CVE-2013-1998: X.org Libxi

Medium severity, CVSS 6.8. EPSS: 2.8% chance of exploitation in the next 30 days.

Multiple buffer overflows in X.org libXi 1.7.1 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XGetDeviceButtonMapping, (2) XIPassiveGrabDevice, and (3) XQueryDeviceState functions.

Affected products

  • X.org Libxi: up to and including 1.7.1; version 1.5.0 only; version 1.5.99.2 only; version 1.5.99.3 only; version 1.6.0 only; version 1.6.1 only; …

Published 2013-06-15. Last modified 2026-06-16.