CVE Tools

Libxfont

18 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Libxfont, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Libxfont CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Libxfont CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-073
2026-080
2026-091

Severity

How the 18 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical422%
  • High1161%
  • Medium211%
  • Low16%

Latest CVEs

The 15 most recently published vulnerabilities affecting Libxfont.

  1. CVE-2026-44950fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont29.0
  2. CVE-2026-56003libXfont2 computeProps Property Buffer Heap Buffer Overflow8.5
  3. CVE-2026-56002libXfont2 PCF Font Parsing Heap Buffer Overflow8.5
  4. CVE-2026-56001libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow8.5
  5. CVE-2017-16611In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be trig...5.5
  6. CVE-2017-13720In the PatternMatch function in fontfile/fontdir.c in libXfont through 1.5.2 and 2.x before 2.0.2, an attacker with access to an X connection can cause a buffer over-read during pattern matching of...7.1
  7. CVE-2017-13722In the pcfGetProperties function in bitmap/pcfread.c in libXfont through 1.5.2 and 2.x before 2.0.2, a missing boundary check (for PCF files) could be used by local attackers authenticated to an Xs...7.1
  8. CVE-2007-5199A single byte overflow in catalogue.c in X.Org libXfont 1.3.1 allows remote attackers to have unspecified impact.9.8
  9. CVE-2015-1804The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly perform type conversion for metrics values, which allows remote authentica...8.5
  10. CVE-2015-1803The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated...8.5
  11. CVE-2015-1802The bdfReadProperties function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 allows remote authenticated users to cause a denial of service (out-of-bounds write and cras...8.5
  12. CVE-2014-0209Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a ...4.6
  13. CVE-2014-0211Multiple integer overflows in the (1) fs_get_reply, (2) fs_alloc_glyphs, and (3) fs_read_extent_info functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers ...7.5
  14. CVE-2014-0210Multiple buffer overflows in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs protocol reply to the (1) _fs_recv_conn_s...7.5
  15. CVE-2013-6462Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execut...9.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store