Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Xkbcommon

First CVE: Aug 25, 2018Active for: 8 yearsTotal CVEs: 11

Xkbcommon is a keyboard-handling library embedded across Linux desktop environments and input-processing pipelines, where its narrow product scope belies significant downstream reach. Vulnerabilities in this library recur through memory-management and resource-control weakness classes including NULL-pointer dereferences, infinite loops, uncontrolled resource consumption, and use-after-free conditions, reflecting the complexity of state management in keyboard-layout and input-event parsing. Defenders should track patches to this library as part of broader desktop and input-stack updates; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 91% of tracked vendors
5.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Xkbcommon over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 25, 2018
7 years ago
Most Recent CVE
Aug 25, 2018
2,890 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-15857HIGH
An invalid free in ExprAppendMultiKeysymList in xkbcomp/ast-build.c in xkbcommon before 0.8.1 could be used by local attackers to crash xkbcommon keymap parsers or possibly have un
Aug 25, 20187.825NONO
CVE-2018-15861MEDIUM
Unchecked NULL pointer usage in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser
Aug 25, 20185.521NONO
CVE-2018-15853MEDIUM
Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap
Aug 25, 20185.521NONO
CVE-2018-15864MEDIUM
Unchecked NULL pointer usage in resolve_keysym in xkbcomp/parser.y in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon pars
Aug 25, 20185.520NONO
CVE-2018-15863MEDIUM
Unchecked NULL pointer usage in ResolveStateAndPredicate in xkbcomp/compat.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbc
Aug 25, 20185.520NONO
CVE-2018-15862MEDIUM
Unchecked NULL pointer usage in LookupModMask in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser
Aug 25, 20185.520NONO
CVE-2018-15859MEDIUM
Unchecked NULL pointer usage when parsing invalid atoms in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer derefe
Aug 25, 20185.520NONO
CVE-2018-15858MEDIUM
Unchecked NULL pointer usage when handling invalid aliases in CopyKeyAliasesToKeymap in xkbcomp/keycodes.c in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL
Aug 25, 20185.520NONO
CVE-2018-15856MEDIUM
An infinite loop when reaching EOL unexpectedly in compose/parser.c (aka the keymap parser) in xkbcommon before 0.8.1 could be used by local attackers to cause a denial of service
Aug 25, 20185.520NONO
CVE-2018-15855MEDIUM
Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file,
Aug 25, 20185.520NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
91%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local11 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low11 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Xkbcommon.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Xkbcommon — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Xkbcommon's Products

View all 1 CNAs →

Top CWEs