← Back

Freedesktop

freedesktop

150 CVEs • 23 products

Products (23)

Click to collapse
Toggle
Poppler
poppler
Dbus
dbus
Xdg Utils
xdg-utils
Udisks
udisks
Libinput
libinput
Policykit
policykit
Dbus Glib
dbus-glib
Libbsd
libbsd
Polkit
polkit
Dbus1.0
dbus1.0
Dbus1.1.0
dbus1.1.0
Scratchbox2
scratchbox2
Colord
colord
Libdbus
libdbus
Spice Gtk
spice-gtk
Virglrenderer
virglrenderer
Xdg User Dirs
xdg-user-dirs
Libice
libice

CVEs (150)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Freedesktop
1Libinput
Jul 22, 2026
Jun 4, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
1Freedesktop
1Gst Plugins Good
Jun 17, 2026
May 14, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before performing division oper...Show more
An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.Show less
1Freedesktop
1Gst Plugins Good
Jun 17, 2026
May 14, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before performing division oper...Show more
An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.Show less
2Fedoraproject
Freedesktop
2Fedora
Libinput
Jun 17, 2026
Apr 1, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is call...Show more
A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location is re-used, leading to information disclosure. For this exploit to work, Lua plugins must be enabled in libinput and loaded by the compositor.Show less
2Fedoraproject
Freedesktop
2Fedora
Libinput
Jul 15, 2026
Apr 1, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run una...Show more
A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.Show less
2Freedesktop
Redhat
3Enterprise Linux
Openshift Container PlatformPolkit
Jun 17, 2026
Mar 26, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to...Show more
A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of Service (DoS) for the system.Show less
4Debian
FreedesktopGstreamer+1 more
4Debian Linux
Enterprise LinuxGst Plugins Good+1 more
Jun 17, 2026
Mar 23, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) use...Show more
An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes than validated, causing OOB read.Show less
2Freedesktop
Redhat
2Enterprise Linux
Udisks
Jun 17, 2026
Feb 25, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporti...Show more
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations. This weakens the confidentiality guarantees of encrypted storage volumes.Show less
2Freedesktop
Redhat
2Enterprise Linux
Udisks
Jul 15, 2026
Feb 25, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instru...Show more
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys and render encrypted volumes inaccessible. Successful exploitation results in a denial-of-service condition through irreversible data loss.Show less
1Freedesktop
1Poppler
Jul 5, 2026
Aug 4, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS).
1Freedesktop
1Poppler
Jun 17, 2026
Jul 2, 2025
5.5 MEDIUM· v4
5.9 MEDIUM· v3
N/A· v2
Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-afte...Show more
Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patches the issue.Show less
1Freedesktop
1Poppler
Jun 17, 2026
Apr 18, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.
1Freedesktop
1Poppler
Jun 17, 2026
Apr 5, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.
1Freedesktop
1Poppler
Jun 17, 2026
Apr 5, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.
1Freedesktop
1Poppler
Jun 17, 2026
Dec 23, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.
2Freedesktop
Redhat
2Enterprise Linux
Poppler
Jun 17, 2026
Jun 21, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a de...Show more
A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.Show less
1Freedesktop
1Poppler
Jun 17, 2026
Aug 22, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.
1Freedesktop
1Poppler
Jun 17, 2026
Aug 22, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.
2Debian
Freedesktop
2Debian Linux
Poppler
Jun 17, 2026
Aug 22, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file.
2Debian
Freedesktop
2Debian Linux
Poppler
Jun 17, 2026
Aug 22, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog pro...Show more
In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the incomplete patch of CVE-2018-20662.Show less