Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Freedesktop

First CVE: Jul 30, 2007Active for: 19 yearsTotal CVEs: 152
45.0
VTI Score
High

Freedesktop's vulnerability footprint spans a small set of fundamental desktop and system-integration libraries and utilities—including PDF rendering, inter-process communication, device management, and standards-based configuration handling—that are embedded across a broad range of Linux distributions and graphical environments, placing them among the most prominent infrastructure components in the open-source desktop ecosystem. The recurring weakness classes, including improper input validation, NULL-pointer dereferences, out-of-bounds reads, buffer-boundary violations, and integer overflows, reflect the low-level parsing and memory-management demands of components that operate at the system boundary and handle untrusted input from files, configuration sources, and network protocols. Vulnerabilities in these libraries propagate quickly across the ecosystem because remediation depends on distribution maintainers rebuilding and reissuing affected packages; a single flaw in a foundational library can affect hundreds of downstream applications simultaneously. Defenders should treat Freedesktop component updates as high-priority, inventory affected packages across their environments, and pay particular attention to components like Poppler that routinely process untrusted content such as PDFs. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
152
Total CVEs
More Total CVEs than 99% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.7%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Freedesktop over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 30, 2007
18 years ago
Most Recent CVE
Jun 4, 2026
50 days ago

Products(23 total)

Top CVEs

Signals from CVEs in this vendor scope (152 CVEs).

152 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-30860HIGH
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.
Aug 24, 20217.891YESNO
CVE-2026-50292CRITICAL
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
Jun 4, 20269.841NONO
CVE-2013-0292HIGH
The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gai
Mar 5, 20137.235NOYES
CVE-2012-3524MEDIUM
libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code v
Sep 18, 20126.935NOYES
CVE-2026-35093HIGH
A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restricti
Apr 1, 20268.834NONO
CVE-2012-4425MEDIUM
libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYS
Sep 18, 20126.933NOYES
CVE-2026-46470CRITICAL
An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate a
May 14, 20269.131NONO
CVE-2019-9631CRITICAL
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.
Mar 8, 20199.831NONO
CVE-2017-2820HIGH
An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an int
Jul 12, 20178.830NONO
CVE-2021-3185CRITICAL
A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corrupt
Jan 26, 20219.829NONO
View all 152 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products152 CVEs
13%
51%
32%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local46 (30.3%)
Network68 (44.7%)
Unknown38 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low110 (72.4%)
High4 (2.6%)
Unknown38 (25.0%)
User Interaction
None43 (28.3%)
Unknown38 (25.0%)
Required71 (46.7%)
Privileges Required
Low24 (15.8%)
High0 (0.0%)
None90 (59.2%)
Unknown38 (25.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (152 CVEs).

CISA KEV
1 CVE
0.7% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
3.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Freedesktop.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Freedesktop — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Freedesktop's Products

View all 7 CNAs →

Top CWEs