X11

Vendor:

First CVE: Jul 1, 1997 · Active for 29 years

19
Total CVEs
More Total CVEs than 94% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact X11 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 1, 1997
29 years ago
Most Recent CVE
Apr 16, 2015
4,121 days ago

CVE Severity & Scoring

X1119 CVEs
All CVEs352,785 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown19 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown19 (100.0%)
User Interaction
None0 (0.0%)
Unknown19 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown19 (100.0%)

Top CVEs

Signals from CVEs in this product scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
Jul 1, 199710.054NOYES
Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via fo
May 18, 201210.030NONO
Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 before 1.6.0 allow remote attackers to have unspecified imp
Apr 16, 20157.524NONO
The RandR extension in XFree86 4.2.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users t
Dec 10, 20146.524NONO
The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users
Dec 10, 20146.524NONO
Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, al
Apr 6, 20079.024NONO
Multiple integer overflows in the GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow rem
Dec 10, 20146.523NONO
The GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to ca
Dec 10, 20146.522NONO
The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X) X11R6.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remo
Dec 10, 20146.522NONO
The SProcXFixesSelectSelectionInput function in the XFixes extension in X.Org X Window System (aka X11 or X) X11R6.8.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3
Dec 10, 20146.521NONO

Exploit Exposure

Signals from CVEs in this product scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
5.3% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (19 CVEs).

Media Mentions

Signals from CVEs in this product scope (19 CVEs).

Top CNAs Publishing CVEs For X11

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
r7.316.81.6%00
7.1_1.1.029.513.0%01
6.917.54.3%00
6.8.217.54.3%00
6.8.117.54.3%00
6.8.017.54.3%00
6.816.54.4%00
6.766.74.5%00
6.617.54.3%00
6.5.117.54.3%00
6.4.124.50.4%00
6.417.54.3%00
6.317.54.3%00
6.127.04.3%00
6.027.04.5%00
5.026.10.5%00
4.016.54.4%00
1.11110.02.7%00
1.016.54.4%00