X.org
- Products in analyzed data
- 6
- Catalog vulnerabilities
- 178
Severity across 18 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 18 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, X.org recorded 5 security vulnerabilities in the last 90 days across 4 products, including 5 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, libXfont2 had the most security vulnerabilities in the X.org ecosystem, with 3 vulnerabilities—approximately 60% of the provider's total vulnerabilities during this period.
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-56003libXfont2 computeProps Property Buffer Heap Buffer Overflow | Exploitation statusNot known exploited | FixYes | Affected productlibXfont2 | Published07/08/2026 | SeverityHigh |
CVE-2026-56002libXfont2 PCF Font Parsing Heap Buffer Overflow | Exploitation statusNot known exploited | FixYes | Affected productlibXfont2 | Published07/08/2026 | SeverityHigh |
CVE-2026-56001libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow | Exploitation statusNot known exploited | FixYes | Affected productlibXfont2 | Published07/08/2026 | SeverityHigh |
CVE-2026-55999xorg-server / xwayland glamor font atlas Heap Buffer Overflow | Exploitation statusNot known exploited | FixYes | Affected productxorg-server | Published07/08/2026 | SeverityHigh |
CVE-2026-56000xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent() | Exploitation statusNot known exploited | FixYes | Affected productxorg-x11-server | Published07/08/2026 | SeverityCritical |
CVE-2026-50263Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow() | Exploitation statusNot known exploited | FixNot confirmed | Affected productRed Hat Enterprise Linux 10 | Published06/05/2026 | SeverityMedium |
CVE-2026-50262Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes | Exploitation statusNot known exploited | FixNot confirmed | Affected productRed Hat Enterprise Linux 10 | Published06/05/2026 | SeverityMedium |
CVE-2026-50264Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds heap write in dri2 drigetbuffers/drigetbufferswithformat | Exploitation statusNot known exploited | FixNot confirmed | Affected productRed Hat Enterprise Linux 10 | Published06/05/2026 | SeverityHigh |
CVE-2026-50261Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter() | Exploitation statusNot known exploited | FixNot confirmed | Affected productRed Hat Enterprise Linux 10 | Published06/05/2026 | SeverityHigh |
CVE-2026-50260Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter() | Exploitation statusNot known exploited | FixNot confirmed | Affected productRed Hat Enterprise Linux 10 | Published06/05/2026 | SeverityHigh |
CVE-2026-50258Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levels | Exploitation statusNot known exploited | FixNot confirmed | Affected productRed Hat Enterprise Linux 10 | Published06/05/2026 | SeverityHigh |
CVE-2026-50259Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexing | Exploitation statusNot known exploited | FixNot confirmed | Affected productRed Hat Enterprise Linux 10 | Published06/05/2026 | SeverityHigh |
CVE-2026-50256Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatch | Exploitation statusNot known exploited | FixNot confirmed | Affected productRed Hat Enterprise Linux 10 | Published06/05/2026 | SeverityHigh |
CVE-2026-50257Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence() | Exploitation statusNot known exploited | FixNot confirmed | Affected productRed Hat Enterprise Linux 10 | Published06/05/2026 | SeverityHigh |
CVE-2026-34002Xorg: xwayland: x.org x server: information disclosure or denial of service via out-of-bounds read in xkb modifier map handling | Exploitation statusNot known exploited | FixNot confirmed | Affected productRed Hat Enterprise Linux 10.0 Extended Update Support | Published05/05/2026 | SeverityMedium |
CVE-2026-34000Xwayland: xorg: x.org x server: information disclosure and denial of service via out-of-bounds read in xkb geometry processing. | Exploitation statusNot known exploited | FixNot confirmed | Affected productRed Hat Enterprise Linux 10.0 Extended Update Support | Published05/05/2026 | SeverityMedium |
CVE-2025-62229Xorg: xmayland: use-after-free in xpresentnotify structure creation | Exploitation statusNot known exploited | FixYes | Affected productxwayland | Published10/30/2025 | SeverityHigh |
CVE-2025-62230Xorg: xwayland: use-after-free in xkb client resource removal | Exploitation statusNot known exploited | FixYes | Affected productxwayland | Published10/30/2025 | SeverityHigh |
CVE-2025-62231Xorg: xmayland: value overflow in xkbsetcompatmap() | Exploitation statusNot known exploited | FixYes | Affected productxwayland | Published10/30/2025 | SeverityHigh |
CVE-2025-49180Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x resize, rotate and reflect (randr) extension | Exploitation statusNot known exploited | FixYes | Affected productxwayland | Published06/17/2025 | SeverityHigh |
CVE-2025-49179Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x record extension | Exploitation statusNot known exploited | FixYes | Affected productxwayland | Published06/17/2025 | SeverityHigh |
CVE-2025-49178Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: unprocessed client request due to bytes to ignore | Exploitation statusNot known exploited | FixYes | Affected productxwayland | Published06/17/2025 | SeverityMedium |
CVE-2025-49177Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: data leak in xfixes extension's xfixessetclientdisconnectmode | Exploitation statusNot known exploited | FixYes | Affected productxwayland | Published06/17/2025 | SeverityMedium |
CVE-2025-49176Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in big requests extension | Exploitation statusNot known exploited | FixYes | Affected productxwayland | Published06/17/2025 | SeverityHigh |
CVE-2025-49175Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: out-of-bounds read in x rendering extension animated cursors | Exploitation statusNot known exploited | FixYes | Affected productxwayland | Published06/17/2025 | SeverityMedium |
CVE-2022-49737CVE-2022-49737 | Exploitation statusPublic exploit | FixNot confirmed | Affected productX server | Published03/16/2025 | SeverityHigh |
CVE-2025-26601Xorg: xwayland: use-after-free in syncinittrigger() | Exploitation statusNot known exploited | FixYes | Affected productxserver | Published02/25/2025 | SeverityHigh |
CVE-2025-26600Xorg: xwayland: use-after-free in playreleasedevents() | Exploitation statusNot known exploited | FixYes | Affected productxserver | Published02/25/2025 | SeverityHigh |
CVE-2025-26599Xorg: xwayland: use of uninitialized pointer in compredirectwindow() | Exploitation statusNot known exploited | FixYes | Affected productxserver | Published02/25/2025 | SeverityHigh |
CVE-2025-26598Xorg: xwayland: out-of-bounds write in createpointerbarrierclient() | Exploitation statusNot known exploited | FixYes | Affected productxserver | Published02/25/2025 | SeverityHigh |
CVE-2025-26597Xorg: xwayland: buffer overflow in xkbchangetypesofkey() | Exploitation statusNot known exploited | FixYes | Affected productxserver | Published02/25/2025 | SeverityHigh |
CVE-2025-26596Xorg: xwayland: heap overflow in xkbwritekeysyms() | Exploitation statusNot known exploited | FixYes | Affected productxserver | Published02/25/2025 | SeverityHigh |
CVE-2025-26595Xorg: xwayland: buffer overflow in xkbvmodmasktext() | Exploitation statusNot known exploited | FixYes | Affected productxserver | Published02/25/2025 | SeverityHigh |
CVE-2025-26594X.org: xwayland: use-after-free of the root cursor | Exploitation statusNot known exploited | FixYes | Affected productxserver | Published02/25/2025 | SeverityHigh |
CVE-2024-0229Xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access | Exploitation statusNot known exploited | FixYes | Affected productxorg-server | Published02/09/2024 | SeverityHigh |
CVE-2024-0409Xorg-x11-server: selinux context corruption | Exploitation statusNot known exploited | FixYes | Affected productxorg-server | Published01/18/2024 | SeverityHigh |
CVE-2024-0408Xorg-x11-server: selinux unlabeled glx pbuffer | Exploitation statusNot known exploited | FixYes | Affected productxorg-server | Published01/18/2024 | SeverityMedium |
CVE-2023-6816Xorg-x11-server: heap buffer overflow in devicefocusevent and procxiquerypointer | Exploitation statusNot known exploited | FixNot confirmed | Affected productRed Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | Published01/18/2024 | SeverityCritical |
CVE-2023-6478Xorg-x11-server: out-of-bounds memory read in rrchangeoutputproperty and rrchangeproviderproperty | Exploitation statusNot known exploited | FixNot confirmed | Affected productRed Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | Published12/13/2023 | SeverityHigh |
CVE-2023-6377Xorg-x11-server: out-of-bounds memory reads/writes in xkb button actions | Exploitation statusNot known exploited | FixNot confirmed | Affected productRed Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | Published12/13/2023 | SeverityHigh |
CVE-2023-5574Xorg-x11-server: use-after-free bug in damagedestroy | Exploitation statusNot known exploited | FixNot confirmed | Affected productRed Hat Enterprise Linux 9 | Published10/25/2023 | SeverityHigh |
CVE-2023-5380Xorg-x11-server: use-after-free bug in destroywindow | Exploitation statusNot known exploited | FixNot confirmed | Affected productRed Hat Enterprise Linux 7 | Published10/25/2023 | SeverityMedium |
CVE-2023-5367Xorg-x11-server: out-of-bounds write in xichangedeviceproperty/rrchangeoutputproperty | Exploitation statusNot known exploited | FixNot confirmed | Affected productRed Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | Published10/25/2023 | SeverityHigh |
CVE-2023-43788Libxpm: out of bounds read in xpmcreatexpmimagefrombuffer() | Exploitation statusNot known exploited | FixYes | Affected productlibXpm | Published10/10/2023 | SeverityMedium |
CVE-2023-43787Libx11: integer overflow in xcreateimage() leading to a heap overflow | Exploitation statusNot known exploited | FixYes | Affected productlibX11 | Published10/10/2023 | SeverityHigh |
CVE-2023-43786Libx11: stack exhaustion from infinite recursion in putsubimage() | Exploitation statusNot known exploited | FixYes | Affected productlibXpm | Published10/10/2023 | SeverityMedium |
CVE-2023-43785Libx11: out-of-bounds memory access in _xkbreadkeysyms() | Exploitation statusNot known exploited | FixYes | Affected productlibX11 | Published10/10/2023 | SeverityMedium |
CVE-2023-3138CVE-2023-3138 | Exploitation statusNot confirmed | FixNot confirmed | Affected productlibX11 | Published06/28/2023 | SeverityUnknown |
CVE-2023-1393CVE-2023-1393 | Exploitation statusNot known exploited | FixNot confirmed | Affected productxorg-server | Published03/30/2023 | SeverityHigh |
CVE-2023-0494CVE-2023-0494 | Exploitation statusNot known exploited | FixNot confirmed | Affected productxorg-x11-server | Published03/27/2023 | SeverityHigh |
CVE-2022-4883CVE-2022-4883 | Exploitation statusNot known exploited | FixNot confirmed | Affected productlibXpm | Published02/07/2023 | SeverityHigh |
CVE-2022-46285CVE-2022-46285 | Exploitation statusNot known exploited | FixNot confirmed | Affected productlibXpm | Published02/07/2023 | SeverityHigh |
CVE-2022-44617CVE-2022-44617 | Exploitation statusNot known exploited | FixNot confirmed | Affected productlibXpm | Published02/06/2023 | SeverityHigh |
CVE-2022-46341CVE-2022-46341 | Exploitation statusNot known exploited | FixNot confirmed | Affected productxorg-x11-server | Published12/14/2022 | SeverityHigh |
CVE-2022-46340CVE-2022-46340 | Exploitation statusNot known exploited | FixNot confirmed | Affected productxorg-x11-server | Published12/14/2022 | SeverityHigh |
CVE-2022-46344CVE-2022-46344 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published12/14/2022 | SeverityUnknown |
CVE-2022-4283CVE-2022-4283 | Exploitation statusNot known exploited | FixNot confirmed | Affected productxorg-x11-server | Published12/14/2022 | SeverityHigh |
CVE-2022-46342CVE-2022-46342 | Exploitation statusNot known exploited | FixNot confirmed | Affected productxorg-x11-server | Published12/14/2022 | SeverityHigh |
CVE-2022-46343CVE-2022-46343 | Exploitation statusNot known exploited | FixNot confirmed | Affected productxorg-x11-server | Published12/14/2022 | SeverityHigh |
CVE-2022-3550X.org Server xkb.c _GetCountedString buffer overflow | Exploitation statusNot known exploited | FixNot confirmed | Affected productServer | Published10/17/2022 | SeverityMedium |
CVE-2022-3553X.org Server xquartz X11Controller.m denial of service | Exploitation statusNot known exploited | FixNot confirmed | Affected productServer | Published10/17/2022 | SeverityLow |
CVE-2022-3551X.org Server xkb.c ProcXkbGetKbdByName memory leak | Exploitation statusNot known exploited | FixNot confirmed | Affected productServer | Published10/17/2022 | SeverityLow |
CVE-2022-2319CVE-2022-2319 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published09/01/2022 | SeverityUnknown |
CVE-2022-2320CVE-2022-2320 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published09/01/2022 | SeverityUnknown |
CVE-2021-4008CVE-2021-4008 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published12/17/2021 | SeverityUnknown |
CVE-2021-4010CVE-2021-4010 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published12/17/2021 | SeverityUnknown |
CVE-2021-4011CVE-2021-4011 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published12/17/2021 | SeverityUnknown |
CVE-2021-4009CVE-2021-4009 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published12/17/2021 | SeverityUnknown |
CVE-2021-31535CVE-2021-31535 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published05/27/2021 | SeverityUnknown |
CVE-2020-25697CVE-2020-25697 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published05/26/2021 | SeverityUnknown |
CVE-2021-3472CVE-2021-3472 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published04/26/2021 | SeverityUnknown |
CVE-2020-14360CVE-2020-14360 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published01/20/2021 | SeverityUnknown |
CVE-2020-25712CVE-2020-25712 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published12/15/2020 | SeverityUnknown |
CVE-2020-14345CVE-2020-14345 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published09/15/2020 | SeverityUnknown |
CVE-2020-14362CVE-2020-14362 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published09/15/2020 | SeverityUnknown |
CVE-2020-14361CVE-2020-14361 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published09/15/2020 | SeverityUnknown |
CVE-2020-14346CVE-2020-14346 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published09/15/2020 | SeverityUnknown |
CVE-2020-14363CVE-2020-14363 | Exploitation statusNot confirmed | FixNot confirmed | Affected productlibX11 | Published09/11/2020 | SeverityHigh |
CVE-2020-14347CVE-2020-14347 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published08/05/2020 | SeverityMedium |
CVE-2020-14344CVE-2020-14344 | Exploitation statusNot confirmed | FixNot confirmed | Affected productlibX11 | Published08/05/2020 | SeverityMedium |
CVE-2019-17624CVE-2019-17624 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published10/16/2019 | SeverityUnknown |
CVE-2018-14665CVE-2018-14665 | Exploitation statusPublic exploit | FixNot confirmed | Affected productNot confirmed | Published10/25/2018 | SeverityUnknown |
CVE-2018-14599CVE-2018-14599 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published08/24/2018 | SeverityUnknown |
CVE-2018-14600CVE-2018-14600 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published08/24/2018 | SeverityUnknown |
CVE-2018-14598CVE-2018-14598 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published08/24/2018 | SeverityUnknown |
CVE-2017-2624CVE-2017-2624 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published07/27/2018 | SeverityMedium |
CVE-2017-2625CVE-2017-2625 | Exploitation statusNot confirmed | FixNot confirmed | Affected productlibXdmcp | Published07/27/2018 | SeverityMedium |
CVE-2017-12187CVE-2017-12187 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published01/24/2018 | SeverityUnknown |
CVE-2017-12183CVE-2017-12183 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published01/24/2018 | SeverityUnknown |
CVE-2017-12177CVE-2017-12177 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published01/24/2018 | SeverityUnknown |
CVE-2017-12182CVE-2017-12182 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published01/24/2018 | SeverityUnknown |
CVE-2017-12185CVE-2017-12185 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published01/24/2018 | SeverityUnknown |
CVE-2017-12181CVE-2017-12181 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published01/24/2018 | SeverityUnknown |
CVE-2017-12184CVE-2017-12184 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published01/24/2018 | SeverityUnknown |
CVE-2017-12178CVE-2017-12178 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published01/24/2018 | SeverityUnknown |
CVE-2017-12176CVE-2017-12176 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published01/24/2018 | SeverityUnknown |
CVE-2017-12186CVE-2017-12186 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published01/24/2018 | SeverityUnknown |
CVE-2017-12179CVE-2017-12179 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published01/24/2018 | SeverityUnknown |
CVE-2017-12180CVE-2017-12180 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxorg-x11-server | Published01/24/2018 | SeverityUnknown |
CVE-2017-13720CVE-2017-13720 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published10/11/2017 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan