Skip to main content

Vendor archive

freedesktop CVEs

Beta · best-effort

150 CVEs tagged to vendor freedesktop4 Critical, 48 High, 79 Medium, 19 Low, 0 Unrated.

CVE-2026-50292

Published Jun 4, 2026

In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution

CVSS 7.4 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-46470

Published May 14, 2026

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate…

CVSS 4.0 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-46469

Published May 14, 2026

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate…

CVSS 4.0 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-35094

Published Apr 1, 2026

A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a ga…

CVSS 3.3 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-35093

Published Apr 1, 2026

A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrict…

CVSS 8.8 · High
evidence mentions
5
Buzz score
35.9
Vendor/product tagsBeta · best-effort

CVE-2026-26104

Published Feb 25, 2026

A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privil…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-26103

Published Feb 25, 2026

A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue a…

CVSS 7.1 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2025-50420

Published Aug 4, 2025

An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-52886

Published Jul 2, 2025

Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow t…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-43903

Published Apr 18, 2025

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32365

Published Apr 5, 2025

Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.

CVSS 4.0 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-32364

Published Apr 5, 2025

A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.

CVSS 4.0 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2024-56378

Published Dec 23, 2024

libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38349

Published Aug 22, 2023

An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37052

Published Aug 22, 2023

A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37051

Published Aug 22, 2023

An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37050

Published Aug 22, 2023

In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-18839

Published Aug 22, 2023

Buffer Overflow vulnerability in HtmlOutputDev::page in poppler 0.75.0 allows attackers to cause a denial of service.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36024

Published Aug 11, 2023

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 func…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36023

Published Aug 11, 2023

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34872

Published Jul 31, 2023

A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 150 CVEsPage 1 of 6