← Back

Freedesktop

freedesktop

150 CVEs • 23 products

Products (23)

Click to collapse
Toggle
Poppler
poppler
Dbus
dbus
Xdg Utils
xdg-utils
Udisks
udisks
Libinput
libinput
Policykit
policykit
Dbus Glib
dbus-glib
Libbsd
libbsd
Polkit
polkit
Dbus1.0
dbus1.0
Dbus1.1.0
dbus1.1.0
Scratchbox2
scratchbox2
Colord
colord
Libdbus
libdbus
Spice Gtk
spice-gtk
Virglrenderer
virglrenderer
Xdg User Dirs
xdg-user-dirs
Libice
libice

CVEs (150)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Freedesktop
1Poppler
Jun 17, 2026
Dec 25, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones in late December 2020...Show more
DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones in late December 2020, not the 20.12.1 release. In this situation, it should NOT be considered a Poppler vulnerability. However, several third-party Open Source projects directly rely on Poppler git clones made at arbitrary times, and therefore the CVE remains useful to users of those projectsShow less
3Debian
FreedesktopRedhat
3Debian Linux
Enterprise LinuxPoppler
Jun 17, 2026
Dec 3, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash...Show more
A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service.Show less
1Freedesktop
1Accountsservice
Jun 17, 2026
Nov 11, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an inf...Show more
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an infinite loop if /dev/zero is symlinked to this location.Show less
1Freedesktop
1Accountsservice
Jun 17, 2026
Nov 11, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, improperly dropped the ruid, allowing untrusted users to send signals to AccountService, thus stoppi...Show more
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, improperly dropped the ruid, allowing untrusted users to send signals to AccountService, thus stopping it from handling D-Bus messages in a timely fashion.Show less
2Canonical
Freedesktop
2Dbus
Ubuntu Linux
Jun 17, 2026
Jun 8, 2020
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with acces...Show more
An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.Show less
4Freedesktop
OpensuseRedhat+1 more
4Enterprise Linux
OpensusePoppler+1 more
Nov 21, 2024
Jan 9, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
4Canonical
DebianFreedesktop+1 more
4Debian Linux
LeapLibbsd+1 more
Jun 17, 2026
Jan 8, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).
2Debian
Freedesktop
2Debian Linux
Poppler
Nov 21, 2024
Nov 13, 2019
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.
2Debian
Freedesktop
2Debian Linux
Poppler
Nov 21, 2024
Nov 13, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.
1Freedesktop
1Poppler
Nov 21, 2024
Sep 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
Enterprise LinuxFedora+2 more
Jun 17, 2026
Aug 1, 2019
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.
4Debian
FedoraprojectFreedesktop+1 more
7Debian Linux
Enterprise LinuxEnterprise Linux Eus+4 more
Jun 17, 2026
Jul 22, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with...Show more
The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo.Show less
2Canonical
Freedesktop
2Dbus
Ubuntu Linux
Jun 17, 2026
Jun 11, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink...Show more
dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink mishandling in the reference implementation of DBUS_COOKIE_SHA1 in the libdbus library. (This only affects the DBUS_COOKIE_SHA1 authentication mechanism.) A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write in unintended locations. In the worst case, this could result in the DBusServer reusing a cookie that is known to the malicious client, and treating that cookie as evidence that a subsequent client connection came from an attacker-chosen uid, allowing authentication bypass.Show less
1Freedesktop
1Poppler
Jun 17, 2026
May 23, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.
2Fedoraproject
Freedesktop
2Fedora
Poppler
Jun 17, 2026
Apr 8, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc.
1Freedesktop
1Poppler
Jun 17, 2026
Apr 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc.
1Freedesktop
1Poppler
Jun 17, 2026
Apr 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.
1Freedesktop
1Poppler
Jun 17, 2026
Apr 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.
5Canonical
DebianFedoraproject+2 more
8Debian Linux
Enterprise LinuxEnterprise Linux Eus+5 more
Jun 17, 2026
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file...Show more
PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.Show less
3Debian
FedoraprojectFreedesktop
3Debian Linux
FedoraPoppler
Jun 17, 2026
Mar 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.