Fvwm is a lightweight window manager for Unix and Linux systems, maintaining a minimal vulnerability footprint concentrated in its core window-management functionality. The observed weakness classes reflect general input-handling and parsing challenges characteristic of long-lived X11-based tools; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fvwm over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-1308MEDIUM CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a | Dec 31, 2003 | 4.6 | 21 | NO | YES |
CVE-2006-5969MEDIUM CRLF injection vulnerability in the evalFolderLine function in fvwm 2.5.18 and earlier allows local users to execute arbitrary commands via carriage returns in a directory name, wh | Nov 17, 2006 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fvwm.
Media articles that mention a CVE ID that affects a product developed by Fvwm — matched by CVE ID, not by vendor name.