MATE Desktop is a lightweight desktop environment and component suite maintained as a fork of GNOME 2, with a focused vulnerability footprint spanning system utilities such as the document viewer Atril, archive manager Engrampa, screensaver daemon, and settings infrastructure. The observed disclosures cluster around core desktop and system-utility components rather than a broad platform, reflecting the narrower scope of this environment relative to full-featured desktop stacks. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mate Desktop over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-52138CRITICAL Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged to achieve full Remote Command E | Feb 5, 2024 | 9.6 | 26 | NO | NO |
CVE-2023-51698HIGH Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacker immediate access to the targe | Jan 12, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-52076HIGH Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril | Jan 25, 2024 | 7.8 | 24 | NO | NO |
CVE-2018-20681MEDIUM mate-screensaver before 1.20.2 in MATE Desktop Environment allows physically proximate attackers to view screen content and possibly control applications. By unplugging and re-plug | Jan 9, 2019 | 6.1 | 21 | NO | NO |
The default configuration in mate-settings-daemon 1.5.3 allows local users to change the timezone for the system via a crafted D-Bus call. | May 30, 2014 | 2.1 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mate Desktop.
Media articles that mention a CVE ID that affects a product developed by Mate Desktop — matched by CVE ID, not by vendor name.