The (1) GetDatabase and (2) XimParseStringFile functions in X.org libX11 1.5.99.901 (1.6 RC1) and earlier do not restrict the recursion depth when processing directives to include files, which allows X servers to cause a denial of service (stack consumption) via a crafted file.
Multiple buffer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XAllocColorCells, (2) XkbReadGetDeviceInfoReply, (3) XkbReadGeomShapes, (4) XkbReadGetGeometryReply, (5) XkbReadKeySyms, (6) XkbReadKeyActions, (7) XkbReadKeyBehaviors, (8) XkbReadModifierMap, (9) XkbReadExplicitComponents, (10) XkbReadVirtualModMap, (11) XkbReadGetNamesReply, (12) XkbReadGetMapReply, (13) XimXGetReadData, (14) XListFonts, (15) XListExtensions, and (16) XGetFontPath functions.
Multiple integer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XQueryFont, (2) XF86BigfontQueryFont, (3) XListFontsWithInfo, (4) XGetMotionEvents, (5) XListHosts, (6) XGetModifierMapping, (7) XGetPointerMapping, (8) XGetKeyboardMapping, (9) XGetWindowProperty, (10) XGetImage, (11) LoadColornameDB, (12) XrmGetFileDatabase, (13) XimParseStringFile, or (14) TransFileName functions.