Freedesktop records
150 published records for vendor freedesktop.
Researcher profile
- Entered KEV
- 1 · 0.7%
- Weaponized
- 1 · 0.7%
- Pre-auth RCE
- 6
- With a fix record
- 90.7%
- Median publish → KEV
- 71 days
Recurring classes
- CWE-20 Improper Input Validation19
- CWE-476 NULL Pointer Dereference16
- CWE-125 Out-of-bounds Read13
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer12
- CWE-190 Integer Overflow or Wraparound11
- CWE-674 Uncontrolled Recursion6
The weakness classes this vendor ships most often: where to look.
CWEAll records
150 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
84Now | CVE-2021-30860Weaponized | An integer overflow was addressed with improved input validation.apple · ipados · CWE-190 | High7.8 | KEV | 76.0% | Aug 24, 2021 |
40Plan | CVE-2019-9631No exploit | Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.freedesktop · poppler · CWE-125 | Critical9.8 | — | 3.5% | Mar 8, 2019 |
40Plan | CVE-2016-2090No exploit | Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, whifedoraproject · fedora · CWE-119 | Critical9.8 | — | 3.2% | Jan 13, 2017 |
40Plan | CVE-2021-3185No exploit | A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could causefreedesktop · gst-plugins-bad · CWE-120 | Critical9.8 | — | 2.4% | Jan 26, 2021 |
39Monitor | CVE-2026-50292No exploit | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrfreedesktop · libinput · CWE-93 | Critical9.8 | — | 0.5% | Jun 4, 2026 |
37Monitor | CVE-2019-20367No exploit | nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).freedesktop · libbsd · CWE-125 | Critical9.1 | — | 2.8% | Jan 8, 2020 |
36Monitor | CVE-2017-2820No exploit | An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0.freedesktop · poppler · CWE-190 | High8.8 | — | 4.4% | Jul 12, 2017 |
36Monitor | CVE-2019-9200No exploit | A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered bfreedesktop · poppler · CWE-787 | High8.8 | — | 3.5% | Feb 26, 2019 |
36Monitor | CVE-2019-9543No exploit | An issue was discovered in Poppler 0.74.0.freedesktop · poppler · CWE-674 | High8.8 | — | 3.3% | Mar 1, 2019 |
36Monitor | CVE-2015-1877No exploit | The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, debian · debian linux · CWE-77 | High8.8 | — | 3.2% | Jun 2, 2021 |
36Monitor | CVE-2017-2814No exploit | An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.freedesktop · poppler · CWE-119 | High8.8 | — | 2.7% | Jul 12, 2017 |
36Monitor | CVE-2019-10872No exploit | An issue was discovered in Poppler 0.74.0.freedesktop · poppler · CWE-125 | High8.8 | — | 2.7% | Apr 5, 2019 |
36Monitor | CVE-2017-18266No exploit | The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSfreedesktop · xdg-utils · CWE-74 | High8.8 | — | 2.5% | May 10, 2018 |
36Monitor | CVE-2019-12293No exploit | In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heightsfreedesktop · poppler · CWE-125 | High8.8 | — | 2.1% | May 23, 2019 |
36Monitor | CVE-2017-15565No exploit | In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF documefreedesktop · poppler · CWE-476 | High8.8 | — | 2.1% | Oct 17, 2017 |
36Monitor | CVE-2017-2818No exploit | An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.freedesktop · poppler · CWE-119 | High8.8 | — | 2.0% | Jul 12, 2017 |
36Monitor | CVE-2017-1000456No exploit | freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.freedesktop · poppler · CWE-119 | High8.8 | — | 2.0% | Jan 2, 2018 |
36Monitor | CVE-2018-21009No exploit | Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.freedesktop · poppler · CWE-190 | High8.8 | — | 1.9% | Sep 5, 2019 |
36Monitor | CVE-2019-9545No exploit | An issue was discovered in Poppler 0.74.0.freedesktop · poppler · CWE-674 | High8.8 | — | 1.8% | Mar 1, 2019 |
36Monitor | CVE-2026-46470No exploit | An issue was discovered in GStreamer gst-plugins-good before 1.28.2.freedesktop · gst-plugins-good · CWE-369 | Critical9.1 | — | 0.4% | May 14, 2026 |
35Monitor | CVE-2026-35093No exploit | Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode pluginsfreedesktop · libinput · CWE-94 | High8.8 | — | 0.2% | Apr 1, 2026 |
32Monitor | CVE-2013-4473No exploit | Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause afreedesktop · poppler · CWE-119 | High7.5 | — | 7.1% | Nov 23, 2013 |
32Monitor | CVE-2015-8868No exploit | Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to causfedoraproject · fedora · CWE-119 | High7.8 | — | 4.6% | May 6, 2016 |
32Monitor | CVE-2012-2142No exploit | The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escapefreedesktop · poppler | High7.8 | — | 2.9% | Jan 9, 2020 |
32Monitor | CVE-2019-7310No exploit | In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remotfreedesktop · poppler · CWE-125 | High7.8 | — | 2.1% | Feb 2, 2019 |
- CVE-2021-3086084Now
An integer overflow was addressed with improved input validation.
HighCVSS 7.8KEVWeaponizedEPSS 76%apple · ipadosAug 24, 2021
- CVE-2019-963140Plan
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.
CriticalCVSS 9.8No exploitEPSS 4%freedesktop · popplerMar 8, 2019
- CVE-2016-209040Plan
Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, whi
CriticalCVSS 9.8No exploitEPSS 3%fedoraproject · fedoraJan 13, 2017
- CVE-2021-318540Plan
A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause
CriticalCVSS 9.8No exploitEPSS 2%freedesktop · gst-plugins-badJan 26, 2021
- CVE-2026-5029239Monitor
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitr
CriticalCVSS 9.8No exploitEPSS 1%freedesktop · libinputJun 4, 2026
- CVE-2019-2036737Monitor
nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).
CriticalCVSS 9.1No exploitEPSS 3%freedesktop · libbsdJan 8, 2020
- CVE-2017-282036Monitor
An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0.
HighCVSS 8.8No exploitEPSS 4%freedesktop · popplerJul 12, 2017
- CVE-2019-920036Monitor
A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered b
HighCVSS 8.8No exploitEPSS 3%freedesktop · popplerFeb 26, 2019
- CVE-2019-954336Monitor
An issue was discovered in Poppler 0.74.0.
HighCVSS 8.8No exploitEPSS 3%freedesktop · popplerMar 1, 2019
- CVE-2015-187736Monitor
The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables,
HighCVSS 8.8No exploitEPSS 3%debian · debian linuxJun 2, 2021
- CVE-2017-281436Monitor
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.
HighCVSS 8.8No exploitEPSS 3%freedesktop · popplerJul 12, 2017
- CVE-2019-1087236Monitor
An issue was discovered in Poppler 0.74.0.
HighCVSS 8.8No exploitEPSS 3%freedesktop · popplerApr 5, 2019
- CVE-2017-1826636Monitor
The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWS
HighCVSS 8.8No exploitEPSS 2%freedesktop · xdg-utilsMay 10, 2018
- CVE-2019-1229336Monitor
In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights
HighCVSS 8.8No exploitEPSS 2%freedesktop · popplerMay 23, 2019
- CVE-2017-1556536Monitor
In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF docume
HighCVSS 8.8No exploitEPSS 2%freedesktop · popplerOct 17, 2017
- CVE-2017-281836Monitor
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.
HighCVSS 8.8No exploitEPSS 2%freedesktop · popplerJul 12, 2017
- CVE-2017-100045636Monitor
freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.
HighCVSS 8.8No exploitEPSS 2%freedesktop · popplerJan 2, 2018
- CVE-2018-2100936Monitor
Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.
HighCVSS 8.8No exploitEPSS 2%freedesktop · popplerSep 5, 2019
- CVE-2019-954536Monitor
An issue was discovered in Poppler 0.74.0.
HighCVSS 8.8No exploitEPSS 2%freedesktop · popplerMar 1, 2019
- CVE-2026-4647036Monitor
An issue was discovered in GStreamer gst-plugins-good before 1.28.2.
CriticalCVSS 9.1No exploitEPSS 0%freedesktop · gst-plugins-goodMay 14, 2026
- CVE-2026-3509335Monitor
Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins
HighCVSS 8.8No exploitEPSS 0%freedesktop · libinputApr 1, 2026
- CVE-2013-447332Monitor
Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a
HighCVSS 7.5No exploitEPSS 7%freedesktop · popplerNov 23, 2013
- CVE-2015-886832Monitor
Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to caus
HighCVSS 7.8No exploitEPSS 5%fedoraproject · fedoraMay 6, 2016
- CVE-2012-214232Monitor
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape
HighCVSS 7.8No exploitEPSS 3%freedesktop · popplerJan 9, 2020
- CVE-2019-731032Monitor
In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remot
HighCVSS 7.8No exploitEPSS 2%freedesktop · popplerFeb 2, 2019