Windowmaker is a niche window manager and desktop environment that maintains a minimal product footprint centered on the core Windowmaker and wmmon utilities. The recurring vulnerability surface reflects input-handling weaknesses, particularly format-string flaws, which are characteristic of legacy C-based user-interface software and frequently acquire public exploit code. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Windowmaker over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2000-0026HIGH Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password authorization string. | Dec 21, 1999 | 10.0 | 36 | NO | YES |
CVE-2001-1027HIGH Buffer overflow in WindowMaker (aka wmaker) 0.64 and earlier allows remote attackers to execute arbitrary code via a long window title. | Aug 31, 2001 | 10.0 | 27 | NO | NO |
CVE-2000-0018HIGH wmmon in FreeBSD allows local users to gain privileges via the .wmmonrc configuration file. | Dec 22, 1999 | 7.2 | 27 | NO | YES |
CVE-1999-1064HIGH Multiple buffer overflows in WindowMaker 0.52 through 0.60.0 allow attackers to cause a denial of service and possibly execute arbitrary commands by executing WindowMaker with a lo | Aug 22, 1999 | 10.0 | 25 | NO | NO |
CVE-2002-1277HIGH Buffer overflow in Window Maker (wmaker) 0.80.0 and earlier may allow remote attackers to execute arbitrary code via a certain image file that is not properly handled when Window M | Nov 12, 2002 | 7.5 | 22 | NO | NO |
CVE-2004-2714MEDIUM Unspecified vulnerability in Window Maker 0.80.2 and earlier allows attackers to perform unknown actions via format string specifiers in a font specification in WMGLOBAL, probably | Dec 31, 2004 | 6.0 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Windowmaker.
Media articles that mention a CVE ID that affects a product developed by Windowmaker — matched by CVE ID, not by vendor name.