Skip to main content

Vendor archive

freedesktop CVEs

Beta · best-effort

150 CVEs tagged to vendor freedesktop4 Critical, 48 High, 79 Medium, 19 Low, 0 Unrated.

CVE-2013-4474

Published Nov 23, 2013

Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial of service (crash) via format s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2168

Published Jul 3, 2013

The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4 allows local users to…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-1790

Published Apr 9, 2013

poppler/Stream.cc in poppler before 0.22.1 allows context-dependent attackers to have an unspecified impact via vectors that trigger a read of uninitialized memory by the CCITTFax…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1789

Published Apr 9, 2013

splash/Splash.cc in poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splas…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1788

Published Apr 9, 2013

poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger an "invalid memory acces…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0292

Published Mar 5, 2013

The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to ga…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4425

Published Sep 18, 2012

libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SY…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3524

Published Sep 18, 2012

libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4349

Published Dec 10, 2011

Multiple SQL injection vulnerabilities in (1) cd-mapping-db.c and (2) cd-device-db.c in colord before 0.1.15 allow local users to execute arbitrary SQL commands via vectors relate…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2533

Published Jun 22, 2011

The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in /tmp/.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-2200

Published Jun 22, 2011

The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x before 1.2.28, 1.4.x before 1.4.12, and 1.5.x before 1.5.4 does not properly handle a non-nat…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1000

Published Feb 19, 2011

jingle-factory.c in Telepathy Gabble 0.11 before 0.11.7, 0.10 before 0.10.5, and 0.8 before 0.8.15 allows remote attackers to sniff audio and video calls via a crafted google:jing…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3702

Published Nov 5, 2010

The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows co…

CVSS 7.5 · High

CVE-2010-1172

Published Aug 20, 2010

DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-1149

Published Apr 12, 2010

probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discove…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-0750

Published Apr 6, 2010

pkexec.c in pkexec in libpolkit in PolicyKit 0.96 allows local users to determine the existence of arbitrary files via the argument.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-1189

Published Apr 27, 2009

The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote at…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-0068

Published Jan 7, 2009

Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open,…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4311

Published Dec 10, 2008

The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restri…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4984

Published Nov 6, 2008

scratchbox2 1.99.0.24 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/dpkg.#####.tmp, (b) /tmp/missing_deps.#####, and (c) /tmp/sb2-pkg-chk.$tstam…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1658

Published Apr 11, 2008

Format string vulnerability in the grant helper (polkit-grant-helper.c) in PolicyKit 0.7 and earlier allows attackers to cause a denial of service (crash) and possibly execute arb…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 126-150 of 150 CVEsPage 6 of 6