Freedesktop
freedesktop
150 CVEs • 23 products
Products (23)
Click to collapseToggle
Products (23)
Click to collapse
CVEs (150)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution |
An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before performing division oper...Show more |
An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before performing division oper...Show more |
2Fedoraproject Freedesktop2Fedora LibinputJun 17, 2026 Apr 1, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is call...Show more |
2Fedoraproject Freedesktop2Fedora LibinputJul 15, 2026 Apr 1, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run una...Show more |
2Freedesktop Redhat3Enterprise Linux Openshift Container PlatformPolkitJun 17, 2026 Mar 26, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to...Show more |
4Debian FreedesktopGstreamer+1 more4Debian Linux Enterprise LinuxGst Plugins Good+1 moreJun 17, 2026 Mar 23, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) use...Show more |
2Freedesktop Redhat2Enterprise Linux UdisksJun 17, 2026 Feb 25, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporti...Show more |
2Freedesktop Redhat2Enterprise Linux UdisksJul 15, 2026 Feb 25, 2026 N/A· v4 7.1 HIGH· v3 N/A· v2 A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instru...Show more |
An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS). |
Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-afte...Show more |
NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries. |
Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check. |
A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN. |
libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc. |
2Freedesktop Redhat2Enterprise Linux PopplerJun 17, 2026 Jun 21, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a de...Show more |
An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file. |
A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject. |
2Debian Freedesktop2Debian Linux PopplerJun 17, 2026 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file. |
2Debian Freedesktop2Debian Linux PopplerJun 17, 2026 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog pro...Show more |