Xfree86 is a widely deployed open-source X Window System implementation that has historically served as the foundation for graphical environments across Unix and Linux systems, giving its vulnerabilities relevance across a broad installed base despite a narrowly scoped product portfolio. The vendor's disclosures frequently acquire public exploit code, reflecting the accessibility and antiquity of the codebase as well as the appeal of X server vulnerabilities for local privilege escalation and display manipulation. Recurring weakness categories center on input handling and memory safety issues endemic to a large, legacy graphics and protocol handler, and the vendor's slow maintenance cycle has meant that some disclosed issues persist in deployed systems for extended periods. Defenders should prioritize patches affecting X server components, particularly in internet-accessible or multi-user environments, and consider isolating or deprecating older Xfree86 instances in favor of actively maintained X implementations; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xfree86 Project over time
Signals from CVEs in this vendor scope (41 CVEs).
41 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0084HIGH Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitra | Mar 3, 2004 | 10.0 | 48 | NO | YES |
CVE-2004-0083HIGH Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) | Mar 3, 2004 | 10.0 | 46 | NO | YES |
CVE-2002-1317HIGH Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary cod | Dec 11, 2002 | 7.5 | 40 | NO | YES |
CVE-2001-1178HIGH Buffer overflow in xman allows local users to gain privileges via a long MANPATH environment variable. | Jul 11, 2001 | 7.2 | 29 | NO | YES |
CVE-2001-1086HIGH XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized a | Jul 4, 2001 | 7.5 | 29 | NO | YES |
CVE-1999-0126HIGH SGI IRIX buffer overflow in xterm and Xaw allows root access. | May 3, 1998 | 7.2 | 29 | NO | YES |
CVE-2004-0914HIGH Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) dire | Jan 10, 2005 | 10.0 | 28 | NO | NO |
CVE-2003-0730HIGH Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-b | Oct 20, 2003 | 7.5 | 26 | NO | NO |
CVE-1999-0241HIGH Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm. | Nov 1, 1995 | 10.0 | 26 | NO | NO |
CVE-2006-6102HIGH Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code | Dec 31, 2006 | 10.0 | 25 | NO | NO |
Signals from CVEs in this vendor scope (41 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xfree86 Project.
Media articles that mention a CVE ID that affects a product developed by Xfree86 Project — matched by CVE ID, not by vendor name.