CVE Tools

LIBX11

19 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for LIBX11, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

LIBX11 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
LIBX11 CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-091

Severity

How the 19 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical632%
  • High632%
  • Medium632%
  • Low15%

Latest CVEs

The 15 most recently published vulnerabilities affecting LIBX11.

  1. CVE-2026-88806libX11 XkbGetMap Reply Heap-based Buffer Overflow7.5
  2. CVE-2023-43787Libx11: integer overflow in xcreateimage() leading to a heap overflow7.8
  3. CVE-2023-43786Libx11: stack exhaustion from infinite recursion in putsubimage()5.5
  4. CVE-2023-43785Libx11: out-of-bounds memory access in _xkbreadkeysyms()6.5
  5. CVE-2023-3138A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within ...7.5
  6. CVE-2021-31535LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor request (intended for server-side color lookup) contai...9.8
  7. CVE-2020-14363An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases,...7.8
  8. CVE-2020-14344An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when se...6.7
  9. CVE-2018-14598An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overflows, causing a variable to be set to NULL that w...7.5
  10. CVE-2018-14599An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unsp...9.8
  11. CVE-2018-14600An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resulting in an out-of-bounds write (of up to 128 byt...9.8
  12. CVE-2016-7943The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, which trigger out-of-bounds write operations.9.8
  13. CVE-2016-7942The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, which triggers out-of-bounds read operations.9.8
  14. CVE-2013-7439Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 before 1.6.0 allow remote attackers to have unspecified impact via a crafted...7.5
  15. CVE-2013-1997Multiple buffer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index value...6.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store