SDDM is a lightweight display manager for Linux desktop environments that handles user authentication and session initialization at the graphical login layer. Its narrow, specialized focus on authentication and session management yields recurring vulnerabilities centered on race conditions in shared resources, improper authentication logic, insufficient session expiration controls, and missing authentication checks on critical functions—weaknesses that directly reflect the sensitive nature of login infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sddm Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-7272HIGH Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, | Mar 8, 2018 | 7.8 | 25 | NO | NO |
CVE-2014-7271HIGH Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication. | Mar 8, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-14345HIGH An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not checked for users with an already existing session. Any user with access t | Jul 17, 2018 | 7.5 | 23 | NO | NO |
CVE-2020-28049MEDIUM An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection t | Nov 4, 2020 | 6.3 | 21 | NO | NO |
CVE-2015-0856MEDIUM daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain theme | Nov 24, 2015 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sddm Project.
Media articles that mention a CVE ID that affects a product developed by Sddm Project — matched by CVE ID, not by vendor name.