The Xcb Project maintains a lean, foundational X11 protocol library that, despite its narrow product scope, is embedded deeply in many Linux desktop and server environments as a core graphics and windowing dependency. The observed weakness classes cluster around memory-safety issues including unchecked return values, double frees, use-after-free conditions, and out-of-bounds reads, reflecting the low-level protocol-handling demands of a native C binding library. Current exploitation activity, severity distribution, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xcb Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26957CRITICAL An issue was discovered in the xcb crate through 2021-02-04 for Rust. It has a soundness violation because there is an out-of-bounds read in xcb::xproto::change_property(), as demo | Feb 9, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-26956CRITICAL An issue was discovered in the xcb crate through 2021-02-04 for Rust. It has a soundness violation because bytes from an X server can be interpreted as any data type returned by xc | Feb 9, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-26955CRITICAL An issue was discovered in the xcb crate through 2021-02-04 for Rust. It has a soundness violation because xcb::xproto::GetAtomNameReply::name() calls std::str::from_utf8_unchecked | Feb 9, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-26958HIGH An issue was discovered in the xcb crate through 2021-02-04 for Rust. It has a soundness violation because transmutation to the wrong type can happen after xcb::base::cast_event us | Feb 9, 2021 | 8.8 | 26 | NO | NO |
CVE-2020-36205MEDIUM An issue was discovered in the xcb crate through 2020-12-10 for Rust. base::Error does not have soundness. Because of the public ptr field, a use-after-free or double-free can occu | Jan 26, 2021 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xcb Project.
Media articles that mention a CVE ID that affects a product developed by Xcb Project — matched by CVE ID, not by vendor name.