X's vulnerability footprint spans a foundational graphics and windowing software stack widely used across Unix and Linux systems, with exposure concentrated in core libraries such as libxfont, X11, libx11, and libxcursor. The vendor's disclosures reflect a meaningful share of serious-severity outcomes and recur across weakness classes that are characteristic of low-level graphics and input-handling code: memory-buffer boundary violations, improper input validation, integer overflows, path-traversal conditions, and symlink-following flaws. These weakness patterns carry particular risk in the X Window System context, where libraries operate at a privileged layer and are invoked by a wide variety of client applications, making a single flaw potentially impactful across the entire graphics stack. Defenders should treat updates to X core libraries as systemwide concerns and prioritize patching in production environments where X forwarding or client access is exposed; current severity, exploitation status, and affected-product counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by X over time
Signals from CVEs in this vendor scope (55 CVEs).
55 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56003HIGH A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used | Jul 8, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-56001HIGH A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code withi | Jul 8, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-56002HIGH A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code within the X server. | Jul 8, 2026 | 8.8 | 39 | NO | NO |
CVE-2013-6462HIGH Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) o | Jan 9, 2014 | 9.3 | 35 | NO | NO |
CVE-2011-2895HIGH The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in Open | Aug 19, 2011 | 9.3 | 33 | NO | NO |
CVE-2007-5199CRITICAL A single byte overflow in catalogue.c in X.Org libXfont 1.3.1 allows remote attackers to have unspecified impact. | Aug 18, 2017 | 9.8 | 31 | NO | NO |
CVE-2016-7951CRITICAL Multiple integer overflows in X.org libXtst before 1.2.3 allow remote X servers to trigger out-of-bounds memory access operations by leveraging the lack of range checks. | Dec 13, 2016 | 9.8 | 31 | NO | NO |
CVE-2011-0465HIGH xrdb.c in xrdb before 1.0.9 in X.Org X11R7.6 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a (1) DHCP or (2 | Apr 8, 2011 | 9.3 | 31 | NO | NO |
CVE-2008-2362HIGH Multiple integer overflows in the Render extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via a (1) SProcRenderCreateLinea | Jun 16, 2008 | 10.0 | 29 | NO | NO |
CVE-2015-9262CRITICAL _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow. | Aug 1, 2018 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (55 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by X.
Media articles that mention a CVE ID that affects a product developed by X — matched by CVE ID, not by vendor name.