← Vulnerability feed

Vulnerability record · CVE-2013-1993 · published 15 June 2013

CVE-2013-1993: Mesa3d mesa vulnerability

Mesa3d · Mesa

Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XF86DRIOpenConnection and (2) XF86DRIGetClientDriverName functions.

6.8 CVSS 2.0 Medium EPSS 2.7% · top 14.7% CWE-189 · CWE-189
6.8CVSS 2.0 base score
2.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XF86DRIOpenConnection and (2) XF86DRIGetClientDriverName functions.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-1993 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-40393Mesa3d mesa out-of-bounds write vulnerabilityIn Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an …EPSS 0.62%7.5CVE-2023-45931Mesa3d mesa null pointer dereference vulnerabilityMesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no …EPSS 1.0%6.8CVE-2013-1872Mesa3d mesa memory buffer overflow vulnerabilityThe Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly…EPSS 2.6%6.2CVE-2023-45913Mesa3d mesa null pointer dereference vulnerabilityMesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is trigger…EPSS 0.28%5.3CVE-2023-45919Mesa3d mesa vulnerabilityMesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in …EPSS 0.39%4.4CVE-2019-5068Mesa3d mesa incorrect permission assignment vulnerabilityAn exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the…EPSS 0.48%4.3CVE-2023-45922Mesa3d mesa vulnerabilityglx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute(). NOTE: this is disputed beca…EPSS 0.54%8.4CVE-2013-2094Linux Kernel perf_swevent_init Integer Type Flaw Enables Local Privilege EscalationThe perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, allowing a local user to…KEVEPSS 48%analysed

Source: NIST National Vulnerability Database (record CVE-2013-1993), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.