Skip to main content

Vendor archive

freedesktop CVEs

Beta · best-effort

150 CVEs tagged to vendor freedesktop4 Critical, 48 High, 79 Medium, 19 Low, 0 Unrated.

CVE-2022-4055

Published Nov 19, 2022

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42012

Published Oct 10, 2022

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42011

Published Oct 10, 2022

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42010

Published Oct 10, 2022

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38171

Published Aug 22, 2022

Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1877

Published Jun 2, 2021

The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execut…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27748

Published Jun 1, 2021

A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when bein…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35512

Published Feb 15, 2021

A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3185

Published Jan 26, 2021

A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corrup…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35702

Published Dec 25, 2020

DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-16127

Published Nov 11, 2020

An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled…

CVSS 2.8 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-16126

Published Nov 11, 2020

An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, improperly dropped the ruid, allowing untrusted users to se…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-12049

Published Jun 8, 2020

An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file desc…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-50 of 150 CVEsPage 2 of 6