Freedesktop
freedesktop
150 CVEs • 23 products
Products (23)
Click to collapseToggle
Products (23)
Click to collapse
CVEs (150)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FreedesktopRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Jun 22, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact v...Show more |
3Debian FreedesktopRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Jun 22, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document. |
poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service. |
2Debian Freedesktop2Debian Linux PopplerMay 13, 2026 Jun 2, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of service via a crafted file. |
2Debian Freedesktop2Debian Linux PopplerMay 13, 2026 Jun 2, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows attackers to cause a denial of service via a crafted file. |
poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted documents. |
poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing a...Show more |
Integer overflow in the vrend_create_shader function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (process crash) via crafted pkt_length and offlen values, wh...Show more |
2Freedesktop Redhat2Enterprise Linux PolkitMay 13, 2026 Feb 13, 2017 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibbsd+1 moreMay 13, 2026 Jan 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPoppler+1 moreMay 6, 2026 May 6, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrar...Show more |
D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure e...Show more |
4Canonical DebianFreedesktop+1 more4Dbus Debian LinuxMageia+1 moreMay 6, 2026 Nov 18, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of fi...Show more |
3D Bus Project FreedesktopOpensuse3D Bus DbusOpensuseMay 6, 2026 Oct 25, 2014 N/A· v4 N/A· v3 1.9 LOW· v2 D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors or...Show more |
3D Bus Project FreedesktopOpensuse3D Bus DbusOpensuseMay 6, 2026 Sep 22, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The dbus-daemon in D-Bus before 1.6.24 and 1.8.x before 1.8.8 does not properly close old connections, which allows local users to cause a denial of service (incomplete connection consumption and prevention of new connec...Show more |
3D Bus Project FreedesktopOpensuse3D Bus DbusOpensuseMay 6, 2026 Sep 22, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The bus_connections_check_reply function in config-parser.c in D-Bus before 1.6.24 and 1.8.x before 1.8.8 allows local users to cause a denial of service (CPU consumption) via a large number of method calls. |
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 does not properly close connections for processes that have terminated, which allows local users to cause a denial of service via a D-bus message containing...Show more |
3D Bus Project FreedesktopOpensuse3D Bus DbusOpensuseMay 6, 2026 Sep 22, 2014 N/A· v4 N/A· v3 4.4 MEDIUM· v2 Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allows local users to cause a denial of serv...Show more |
DCTStream.cc in Poppler before 0.13.3 allows remote attackers to cause a denial of service (crash) via a crafted PDF file. |
4Debian FreedesktopMageia Project+1 more4Dbus Debian LinuxMageia+1 moreMay 6, 2026 Jul 19, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6 allows local users to cause a denial of service (disconnect) via a certain sequence of crafted messages that cause the dbus-daemon to forward a message containing an invali...Show more |