← Back

Freedesktop

freedesktop

150 CVEs • 23 products

Products (23)

Click to collapse
Toggle
Poppler
poppler
Dbus
dbus
Xdg Utils
xdg-utils
Udisks
udisks
Libinput
libinput
Policykit
policykit
Dbus Glib
dbus-glib
Libbsd
libbsd
Polkit
polkit
Dbus1.0
dbus1.0
Dbus1.1.0
dbus1.1.0
Scratchbox2
scratchbox2
Colord
colord
Libdbus
libdbus
Spice Gtk
spice-gtk
Virglrenderer
virglrenderer
Xdg User Dirs
xdg-user-dirs
Libice
libice

CVEs (150)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Freedesktop
1Udisks
Apr 29, 2026
Apr 12, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discover encryption keys by (1) running a certai...Show more
probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discover encryption keys by (1) running a certain udevadm command or (2) reading a certain file under /dev/.udev/db/.Show less
1Freedesktop
1Policykit
Apr 29, 2026
Apr 6, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
pkexec.c in pkexec in libpolkit in PolicyKit 0.96 allows local users to determine the existence of arbitrary files via the argument.
1Freedesktop
1Dbus
Apr 23, 2026
Apr 27, 2009
N/A· v4
N/A· v3
3.6 LOW· v2
The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafte...Show more
The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.Show less
1Freedesktop
1Xdg Utils
Apr 23, 2026
Jan 7, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dang...Show more
Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.Show less
1Freedesktop
1Dbus
Apr 23, 2026
Dec 10, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related t...Show more
The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related to send_requested_reply; and possibly (2) receiving messages, related to receive_requested_reply.Show less
1Freedesktop
1Scratchbox2
Apr 23, 2026
Nov 6, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
scratchbox2 1.99.0.24 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/dpkg.#####.tmp, (b) /tmp/missing_deps.#####, and (c) /tmp/sb2-pkg-chk.$tstamp.##### temporary files, related to the (...Show more
scratchbox2 1.99.0.24 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/dpkg.#####.tmp, (b) /tmp/missing_deps.#####, and (c) /tmp/sb2-pkg-chk.$tstamp.##### temporary files, related to the (1) dpkg-checkbuilddeps and (2) sb2-check-pkg-mappings scripts.Show less
1Freedesktop
3Dbus
Dbus1.0Dbus1.1.0
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
2.1 LOW· v2
The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a f...Show more
The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.Show less
1Freedesktop
1Policykit
Apr 23, 2026
Apr 11, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Format string vulnerability in the grant helper (polkit-grant-helper.c) in PolicyKit 0.7 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in a passw...Show more
Format string vulnerability in the grant helper (polkit-grant-helper.c) in PolicyKit 0.7 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in a password.Show less
4Fedoraproject
FreedesktopMandrakesoft+1 more
4Dbus
Enterprise LinuxFedora+1 more
Apr 23, 2026
Feb 29, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intend...Show more
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.Show less
6Apple
CanonicalDebian+3 more
6Cups
Debian LinuxGpdf+3 more
Apr 23, 2026
Jul 30, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might all...Show more
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function.Show less