Xorg might not be the only exploitable software. Here the approach to search for other exploits:
1. Is the software setuid-root?
2. Does the software stay as root?
3. Can you make it write a user description line like as in /etc/shadow?
4. Can you direct it to write to /etc/shadow?
An example: Xorg is setuid-root and stays as root. Pass it the root's description line as a (bogus) font path and it will write an error message. Redirect the error message to /etc/shadow and your exploit is finished.
I am afraid that other setuid-root programs could be exploitable.
setuid-root is extremely dangerous.