CVE-2009-0068 describes an interaction error in xdg-open, affecting freedesktop xdg-utils and Mozilla Firefox, where remote attackers can execute arbitrary code. This occurs when Firefox sends a file with a seemingly safe MIME type to xdg-open, but the underlying file is dangerous, leading xdg-open to process it via automatic type detection. With a CVSS score of 6.8 (Medium), exploitation requires medium attack complexity and could result in partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:freedesktop:xdg-utils:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.