Vulnerabilities > Freedesktop > High

DATE CVE VULNERABILITY TITLE RISK
2024-06-21 CVE-2024-6239 A flaw was found in the Poppler's Pdfinfo utility.
network
low complexity
freedesktop redhat
7.5
2023-08-22 CVE-2020-23804 Uncontrolled Recursion vulnerability in multiple products
Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.
network
low complexity
freedesktop debian CWE-674
7.5
2022-11-19 CVE-2022-4055 Unspecified vulnerability in Freedesktop Xdg-Utils
When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368.
network
low complexity
freedesktop
7.4
2022-08-30 CVE-2022-38784 Integer Overflow or Wraparound vulnerability in multiple products
Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc).
local
low complexity
freedesktop debian fedoraproject CWE-190
7.8
2022-08-22 CVE-2022-38171 Integer Overflow or Wraparound vulnerability in multiple products
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc).
local
low complexity
xpdfreader freedesktop CWE-190
7.8
2022-06-02 CVE-2022-1215 Use of Externally-Controlled Format String vulnerability in Freedesktop Libinput
A format string vulnerability was found in libinput
local
low complexity
freedesktop CWE-134
7.8
2022-06-02 CVE-2022-31782 Out-of-bounds Write vulnerability in Freedesktop Freetype Demo Programs
ftbench.c in FreeType Demo Programs through 2.12.1 has a heap-based buffer overflow.
local
low complexity
freedesktop CWE-787
7.8
2021-08-24 CVE-2021-30860 Integer Overflow or Wraparound vulnerability in multiple products
An integer overflow was addressed with improved input validation.
local
low complexity
apple xpdfreader freedesktop CWE-190
7.8
2021-06-02 CVE-2015-1877 Command Injection vulnerability in multiple products
The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file.
network
low complexity
freedesktop debian CWE-77
8.8
2021-02-15 CVE-2020-35512 Use After Free vulnerability in Freedesktop Dbus 1.12.20
A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID.
local
low complexity
freedesktop CWE-416
7.8