Freedesktop
freedesktop
150 CVEs • 23 products
Products (23)
Click to collapseToggle
Products (23)
Click to collapse
CVEs (150)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Freedesktop2Debian Linux PopplerJun 17, 2026 Aug 22, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input. |
Buffer Overflow vulnerability in HtmlOutputDev::page in poppler 0.75.0 allows attackers to cause a denial of service. |
An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function. |
An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function. |
A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open. |
3Debian FedoraprojectFreedesktop3Dbus Debian LinuxFedoraJun 17, 2026 Jun 8, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic,...Show more |
When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this me...Show more |
2Fedoraproject Freedesktop2Dbus FedoraJun 17, 2026 Oct 10, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a messag...Show more |
2Fedoraproject Freedesktop2Dbus FedoraJun 17, 2026 Oct 10, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a me...Show more |
2Fedoraproject Freedesktop2Dbus FedoraJun 17, 2026 Oct 10, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a me...Show more |
3Debian FedoraprojectFreedesktop3Debian Linux FedoraPopplerJun 17, 2026 Aug 30, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash o...Show more |
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execu...Show more |
1Freedesktop 1Freetype Demo Programs Jun 17, 2026 Jun 2, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 ftbench.c in FreeType Demo Programs through 2.12.1 has a heap-based buffer overflow. |
A format string vulnerability was found in libinput |
3Debian FedoraprojectFreedesktop3Debian Linux FedoraPopplerJun 17, 2026 May 5, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. |
3Apple FreedesktopXpdfreader7Ipados Iphone OsMac Os X+4 moreJun 17, 2026 Aug 24, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PD...Show more |
2Debian Freedesktop2Debian Linux Xdg UtilsNov 21, 2024 Jun 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file. |
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker coul...Show more |
A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID. When...Show more |
1Freedesktop 1Gst Plugins Bad Jun 17, 2026 Jan 26, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution. |