Skip to main content

Vendor/product archive

freedesktop / xdg-utils CVEs

Beta · best-effort

5 CVEs tagged to freedesktop / xdg-utils0 Critical, 3 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2022-4055

Published Nov 19, 2022

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1877

Published Jun 2, 2021

The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execut…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27748

Published Jun 1, 2021

A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when bein…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0068

Published Jan 7, 2009

Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open,…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1