Xlib (LIBX11)
10 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Xlib (LIBX11), a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Xlib (LIBX11) CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 10 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High4
- Medium3
Latest CVEs
The 10 most recently published vulnerabilities affecting Xlib (LIBX11).
- CVE-2023-43787Libx11: integer overflow in xcreateimage() leading to a heap overflow7.8
- CVE-2023-43786Libx11: stack exhaustion from infinite recursion in putsubimage()5.5
- CVE-2023-43785Libx11: out-of-bounds memory access in _xkbreadkeysyms()6.5
- CVE-2023-3138A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within ...7.5
- CVE-2021-31535LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor request (intended for server-side color lookup) contai...9.8
- CVE-2020-14363An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases,...7.8
- CVE-2020-14344An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when se...6.7
- CVE-2018-14598An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overflows, causing a variable to be set to NULL that w...7.5
- CVE-2018-14599An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unsp...9.8
- CVE-2018-14600An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resulting in an out-of-bounds write (of up to 128 byt...9.8
Product grouping is registry-driven, with AI assist and human review. How it works