Linux Mint's vulnerability profile centers on its desktop operating system and associated utilities such as Warpinator, Xreader, and the Cinnamon desktop environment, representing a modestly represented but prominent Linux distribution in the landscape. The recurring weakness classes—path traversal, link-following flaws, deserialization of untrusted data, and improper access control—reflect the file-handling and privilege-boundary challenges inherent to a full-featured desktop and system-utility stack. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Linuxmint over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17080HIGH mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs. This is resolved in | Oct 2, 2019 | 7.8 | 40 | NO | YES |
CVE-2022-42725HIGH Warpinator through 1.2.14 allows access outside of an intended directory, as demonstrated by symbolic directory links. | Oct 10, 2022 | 7.5 | 26 | NO | NO |
CVE-2019-20326HIGH A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4 | Mar 16, 2020 | 7.8 | 26 | NO | NO |
CVE-2012-1567HIGH LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in mintUpdate. | Feb 7, 2020 | 7.5 | 25 | NO | NO |
CVE-2012-1566HIGH LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in mintNanny. | Feb 7, 2020 | 7.5 | 25 | NO | NO |
CVE-2018-13054HIGH An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_fa | Jul 2, 2018 | 8.1 | 25 | NO | NO |
CVE-2023-44452HIGH Linux Mint Xreader CBT File Parsing Argument Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install | May 3, 2024 | 7.8 | 24 | NO | NO |
CVE-2023-44451HIGH Linux Mint Xreader EPUB File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected insta | May 3, 2024 | 7.8 | 24 | NO | NO |
CVE-2014-1949HIGH GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the | Jan 16, 2015 | 7.2 | 24 | NO | NO |
CVE-2023-29380HIGH Warpinator before 1.6.0 allows remote file deletion via directory traversal in top_dir_basenames. | May 29, 2023 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linuxmint.
Media articles that mention a CVE ID that affects a product developed by Linuxmint — matched by CVE ID, not by vendor name.