X Server

Vendor:

First CVE: May 2, 2007 · Active for 19 years

104
Total CVEs
More Total CVEs than 99% of tracked products
6.5
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact X Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2007
19 years ago
Most Recent CVE
Jul 8, 2026
17 days ago

CVE Severity & Scoring

X Server104 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local50 (48.1%)
Network28 (26.9%)
Unknown25 (24.0%)
Physical1 (1.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low73 (70.2%)
High6 (5.8%)
Unknown25 (24.0%)
User Interaction
None79 (76.0%)
Unknown25 (24.0%)
Required0 (0.0%)
Privileges Required
Low62 (59.6%)
High0 (0.0%)
None17 (16.3%)
Unknown25 (24.0%)

Top CVEs

Signals from CVEs in this product scope (104 CVEs).

104 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with th
Oct 25, 20186.657NOYES
Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to Comm
Jul 8, 20267.837NONO
Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFon
Jul 8, 20267.836NONO
A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying
Jun 5, 20267.836NONO
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-afte
Jun 5, 20267.836NONO
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes(
Jun 5, 20267.836NONO
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a st
Jun 5, 20267.836NONO
"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sending ct.c_char 1000 times, an attacker can cause a denial of se
Oct 16, 20197.836NOYES
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments an
Jun 5, 20267.835NONO
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The
Jun 5, 20267.835NONO

Exploit Exposure

Signals from CVEs in this product scope (104 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.0% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
5.8% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (104 CVEs).

Media Mentions

Signals from CVEs in this product scope (104 CVEs).

Top CNAs Publishing CVEs For X Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
21.1.147.80.6%00
21.1.067.80.5%00
1.9.99.90316.54.3%00
1.9.99.90216.54.3%00
1.9.99.90116.54.3%00
1.9.516.54.3%00
1.9.4.90116.54.3%00
1.9.416.54.3%00
1.9.3.90216.54.3%00
1.9.3.90116.54.3%00
1.9.316.54.3%00
1.9.2.90216.54.3%00
1.9.2.90116.54.3%00
1.9.216.54.3%00
1.9.116.54.3%00
1.9.0.90216.54.3%00
1.9.0.90116.54.3%00
1.9.016.54.3%00
1.8.99.90516.54.3%00
1.8.99.90416.54.3%00