Freedesktop's vulnerability footprint spans a small set of fundamental desktop and system-integration libraries and utilities—including PDF rendering, inter-process communication, device management, and standards-based configuration handling—that are embedded across a broad range of Linux distributions and graphical environments, placing them among the most prominent infrastructure components in the open-source desktop ecosystem. The recurring weakness classes, including improper input validation, NULL-pointer dereferences, out-of-bounds reads, buffer-boundary violations, and integer overflows, reflect the low-level parsing and memory-management demands of components that operate at the system boundary and handle untrusted input from files, configuration sources, and network protocols. Vulnerabilities in these libraries propagate quickly across the ecosystem because remediation depends on distribution maintainers rebuilding and reissuing affected packages; a single flaw in a foundational library can affect hundreds of downstream applications simultaneously. Defenders should treat Freedesktop component updates as high-priority, inventory affected packages across their environments, and pay particular attention to components like Poppler that routinely process untrusted content such as PDFs. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freedesktop over time
Signals from CVEs in this vendor scope (152 CVEs).
152 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-30860HIGH An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7. | Aug 24, 2021 | 7.8 | 91 | YES | NO |
CVE-2026-50292CRITICAL In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution | Jun 4, 2026 | 9.8 | 41 | NO | NO |
CVE-2013-0292HIGH The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gai | Mar 5, 2013 | 7.2 | 35 | NO | YES |
CVE-2012-3524MEDIUM libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code v | Sep 18, 2012 | 6.9 | 35 | NO | YES |
CVE-2026-35093HIGH A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restricti | Apr 1, 2026 | 8.8 | 34 | NO | NO |
CVE-2012-4425MEDIUM libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYS | Sep 18, 2012 | 6.9 | 33 | NO | YES |
CVE-2026-46470CRITICAL An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate a | May 14, 2026 | 9.1 | 31 | NO | NO |
CVE-2019-9631CRITICAL Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function. | Mar 8, 2019 | 9.8 | 31 | NO | NO |
CVE-2017-2820HIGH An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an int | Jul 12, 2017 | 8.8 | 30 | NO | NO |
CVE-2021-3185CRITICAL A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corrupt | Jan 26, 2021 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (152 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freedesktop.
Media articles that mention a CVE ID that affects a product developed by Freedesktop — matched by CVE ID, not by vendor name.