Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

FreeBSD: VID-8df49466-5664-11f0-943a-18c04d5ea3dc (CVE-2025-49176): xorg server -- Multiple vulnerabilities

Severity
6
CVSS
(AV:L/AC:L/Au:S/C:P/I:C/A:C)
Published
Jul 1, 2025
Added
Jul 2, 2025
Modified
Jun 15, 2026

Description

A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check.

Solutions

freebsd-upgrade-package-xorg-serverfreebsd-upgrade-package-xephyrfreebsd-upgrade-package-xorg-vfbserverfreebsd-upgrade-package-xorg-nextserverfreebsd-upgrade-package-xwayland
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.