Libxfont
Vendor:
First CVE: Aug 19, 2011 · Active for 14 years
13
Total CVEs
More Total CVEs than 91% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 71% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Libxfont over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 19, 2011
14 years ago
Most Recent CVE
Jul 8, 2026
16 days ago
CVE Severity & Scoring
Libxfont13 CVEs
15%
77%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (7.7%)
Network4 (30.8%)
Unknown8 (61.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (38.5%)
High0 (0.0%)
Unknown8 (61.5%)
User Interaction
None5 (38.5%)
Unknown8 (61.5%)
Required0 (0.0%)
Privileges Required
Low4 (30.8%)
High0 (0.0%)
None1 (7.7%)
Unknown8 (61.5%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56003HIGH A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used | Jul 8, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-56001HIGH A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code withi | Jul 8, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-56002HIGH A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code within the X server. | Jul 8, 2026 | 8.8 | 39 | NO | NO |
CVE-2013-6462HIGH Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) o | Jan 9, 2014 | 9.3 | 35 | NO | NO |
CVE-2011-2895HIGH The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in Open | Aug 19, 2011 | 9.3 | 33 | NO | NO |
CVE-2007-5199CRITICAL A single byte overflow in catalogue.c in X.Org libXfont 1.3.1 allows remote attackers to have unspecified impact. | Aug 18, 2017 | 9.8 | 31 | NO | NO |
CVE-2015-1803HIGH The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows rem | Mar 20, 2015 | 8.5 | 25 | NO | NO |
CVE-2015-1804HIGH The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly perform type conversion for metrics values, which allows | Mar 20, 2015 | 8.5 | 23 | NO | NO |
CVE-2015-1802HIGH The bdfReadProperties function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 allows remote authenticated users to cause a denial of service (out-of-boun | Mar 20, 2015 | 8.5 | 23 | NO | NO |
CVE-2017-16611MEDIUM In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms | Dec 1, 2017 | 5.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Libxfont
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.5.0 | 3 | 8.5 | 4.9% | 0 | 0 |
| 1.4.99 | 3 | 6.5 | 3.0% | 0 | 0 |
| 1.4.6 | 4 | 7.2 | 4.9% | 0 | 0 |
| 1.4.5 | 4 | 7.2 | 4.9% | 0 | 0 |
| 1.4.4 | 4 | 7.2 | 4.9% | 0 | 0 |
| 1.4.3 | 4 | 7.2 | 4.9% | 0 | 0 |
| 1.4.2 | 5 | 7.6 | 5.5% | 0 | 0 |
| 1.4.1 | 5 | 7.6 | 5.5% | 0 | 0 |
| 1.4.0 | 5 | 7.6 | 5.5% | 0 | 0 |
| 1.3.4 | 5 | 7.6 | 5.5% | 0 | 0 |
| 1.3.3 | 5 | 7.6 | 5.5% | 0 | 0 |
| 1.3.2 | 5 | 7.6 | 5.5% | 0 | 0 |
| 1.3.1 | 6 | 8.0 | 5.0% | 0 | 0 |
| 1.3.0 | 5 | 7.6 | 5.5% | 0 | 0 |
| 1.2.9 | 5 | 7.6 | 5.5% | 0 | 0 |
| 1.2.8 | 5 | 7.6 | 5.5% | 0 | 0 |
| 1.2.7 | 5 | 7.6 | 5.5% | 0 | 0 |
| 1.2.6 | 5 | 7.6 | 5.5% | 0 | 0 |
| 1.2.5 | 5 | 7.6 | 5.5% | 0 | 0 |
| 1.2.4 | 5 | 7.6 | 5.5% | 0 | 0 |