CVE-2017-10972: X.org X Server

Medium severity, CVSS 6.5. EPSS: 2.3% chance of exploitation in the next 30 days.

Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.

Affected products

  • X.org X Server: up to and including 1.19.3

Published 2017-07-06. Last modified 2026-06-17.