CVE-1999-0526 describes a critical vulnerability in X servers, specifically affecting x.org X11, where disabled access control (e.g., via "xhost +") permits unauthorized connections. This vulnerability carries a maximum CVSS score of 10.0, indicating a high-severity risk with network-based attacks requiring low complexity and leading to complete compromise of confidentiality, integrity, and availability. While not on the KEV catalog, it has a high EPSS score and FAUCET Risk Score, with Metasploit modules available for keylogging, scanning, and command injection, and has garnered some community and media attention despite its age.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.1_1.1.0CPE matchmatch criteria | cpe:2.3:a:x.org:x11:7.1_1.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.