xfce records
8 published records for vendor xfce.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-125 Out-of-bounds Read1
- CWE-134 Use of Externally-Controlled Format String1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
- CWE-913 Improper Control of Dynamically-Managed Code Resources1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2007-6532No exploit | Double free vulnerability in the Widget Library (libxfcegui4) in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code vixfce · xfce · CWE-119 | Critical10.0 | — | 4.0% | Jan 9, 2008 |
40Plan | CVE-2021-32563No exploit | An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2.xfce · thunar · CWE-913 | Critical9.8 | — | 3.0% | May 11, 2021 |
39Monitor | CVE-2022-45062No exploit | In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.xfce · xfce4-settings · CWE-88 | Critical9.8 | — | 1.5% | Nov 9, 2022 |
36Monitor | CVE-2022-32278No exploit | XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.xfce · exo | High8.8 | — | 1.7% | Jun 13, 2022 |
31Monitor | CVE-2011-1588No exploit | Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.xfce · thunar · CWE-134 | High7.8 | — | 1.1% | Nov 13, 2019 |
28Monitor | CVE-2009-4996No exploit | Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make it easier for physicxfce · xfce · CWE-264 | High7.2 | — | 0.3% | Sep 7, 2010 |
21Monitor | CVE-2007-6531No exploit | Stack-based buffer overflow in the Panel (xfce4-panel) component in Xfce before 4.4.2 might allow remote attackers to execute arbitrary codexfce · xfce · CWE-119 | Medium5.0 | — | 2.9% | Jan 9, 2008 |
18Monitor | CVE-2018-18398No exploit | Xfce Thunar 1.6.15, when Xfce 4.12 is used, mishandles the IBus-Unikey input method for file searches within File Manager, leading to an outxfce · thunar · CWE-125 | Medium4.7 | — | 0.3% | Oct 19, 2018 |
- CVE-2007-653241Plan
Double free vulnerability in the Widget Library (libxfcegui4) in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code vi
CriticalCVSS 10.0No exploitEPSS 4%xfce · xfceJan 9, 2008
- CVE-2021-3256340Plan
An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2.
CriticalCVSS 9.8No exploitEPSS 3%xfce · thunarMay 11, 2021
- CVE-2022-4506239Monitor
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
CriticalCVSS 9.8No exploitEPSS 1%xfce · xfce4-settingsNov 9, 2022
- CVE-2022-3227836Monitor
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
HighCVSS 8.8No exploitEPSS 2%xfce · exoJun 13, 2022
- CVE-2011-158831Monitor
Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.
HighCVSS 7.8No exploitEPSS 1%xfce · thunarNov 13, 2019
- CVE-2009-499628Monitor
Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make it easier for physic
HighCVSS 7.2No exploitEPSS 0%xfce · xfceSep 7, 2010
- CVE-2007-653121Monitor
Stack-based buffer overflow in the Panel (xfce4-panel) component in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code
MediumCVSS 5.0No exploitEPSS 3%xfce · xfceJan 9, 2008
- CVE-2018-1839818Monitor
Xfce Thunar 1.6.15, when Xfce 4.12 is used, mishandles the IBus-Unikey input method for file searches within File Manager, leading to an out
MediumCVSS 4.7No exploitEPSS 0%xfce · thunarOct 19, 2018