Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

X

First CVE: Jun 16, 2008Active for: 18 yearsTotal CVEs: 55
20.7
VTI Score
Low

X's vulnerability footprint spans a foundational graphics and windowing software stack widely used across Unix and Linux systems, with exposure concentrated in core libraries such as libxfont, X11, libx11, and libxcursor. The vendor's disclosures reflect a meaningful share of serious-severity outcomes and recur across weakness classes that are characteristic of low-level graphics and input-handling code: memory-buffer boundary violations, improper input validation, integer overflows, path-traversal conditions, and symlink-following flaws. These weakness patterns carry particular risk in the X Window System context, where libraries operate at a privileged layer and are invoked by a wide variety of client applications, making a single flaw potentially impactful across the entire graphics stack. Defenders should treat updates to X core libraries as systemwide concerns and prioritize patching in production environments where X forwarding or client access is exposed; current severity, exploitation status, and affected-product counts are shown alongside this summary.

FAUCET AI Generated
55
Total CVEs
More Total CVEs than 99% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by X over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 16, 2008
18 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Products(28 total)

Top CVEs

Signals from CVEs in this vendor scope (55 CVEs).

55 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-56003HIGH
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used
Jul 8, 20268.839NONO
CVE-2026-56001HIGH
A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code withi
Jul 8, 20268.839NONO
CVE-2026-56002HIGH
A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.
Jul 8, 20268.839NONO
CVE-2013-6462HIGH
Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) o
Jan 9, 20149.335NONO
CVE-2011-2895HIGH
The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in Open
Aug 19, 20119.333NONO
CVE-2007-5199CRITICAL
A single byte overflow in catalogue.c in X.Org libXfont 1.3.1 allows remote attackers to have unspecified impact.
Aug 18, 20179.831NONO
CVE-2016-7951CRITICAL
Multiple integer overflows in X.org libXtst before 1.2.3 allow remote X servers to trigger out-of-bounds memory access operations by leveraging the lack of range checks.
Dec 13, 20169.831NONO
CVE-2011-0465HIGH
xrdb.c in xrdb before 1.0.9 in X.Org X11R7.6 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a (1) DHCP or (2
Apr 8, 20119.331NONO
CVE-2008-2362HIGH
Multiple integer overflows in the Render extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via a (1) SProcRenderCreateLinea
Jun 16, 200810.029NONO
CVE-2015-9262CRITICAL
_XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow.
Aug 1, 20189.826NONO
View all 55 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products55 CVEs
60%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.8%)
Network7 (12.7%)
Unknown47 (85.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (14.5%)
High0 (0.0%)
Unknown47 (85.5%)
User Interaction
None8 (14.5%)
Unknown47 (85.5%)
Required0 (0.0%)
Privileges Required
Low4 (7.3%)
High0 (0.0%)
None4 (7.3%)
Unknown47 (85.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (55 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by X.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by X — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For X's Products

View all 5 CNAs →

Top CWEs