CVE-1999-0526

EXPLOITED

X Server - Info Disclosure

Title source: llm

Description

An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.

Exploits (3)

metasploit SCANNER
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/x11/open_x11.rb
metasploit WORKING POC
by h00die, nir tzachar · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/x11_keyboard_spy.rb
metasploit WORKING POC EXCELLENT
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/x11/x11_keyboard_exec.rb

Scores

EPSS 0.7265
EPSS Percentile 98.8%

Details

VulnCheck KEV 2025-02-27
Status published
Products (1)
x.org/x11 7.1_1.1.0
Published Jul 01, 1997
Tracked Since Feb 18, 2026