Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sddm Project

First CVE: Nov 24, 2015Active for: 11 yearsTotal CVEs: 5

SDDM is a lightweight display manager for Linux desktop environments that handles user authentication and session initialization at the graphical login layer. Its narrow, specialized focus on authentication and session management yields recurring vulnerabilities centered on race conditions in shared resources, improper authentication logic, insufficient session expiration controls, and missing authentication checks on critical functions—weaknesses that directly reflect the sensitive nature of login infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 83% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sddm Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 24, 2015
10 years ago
Most Recent CVE
Nov 4, 2020
2,088 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-7272HIGH
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory,
Mar 8, 20187.825NONO
CVE-2014-7271HIGH
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.
Mar 8, 20187.825NONO
CVE-2018-14345HIGH
An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not checked for users with an already existing session. Any user with access t
Jul 17, 20187.523NONO
CVE-2020-28049MEDIUM
An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection t
Nov 4, 20206.321NONO
CVE-2015-0856MEDIUM
daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain theme
Nov 24, 20154.614NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
40%
60%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (60.0%)
Network1 (20.0%)
Unknown1 (20.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (40.0%)
High2 (40.0%)
Unknown1 (20.0%)
User Interaction
None4 (80.0%)
Unknown1 (20.0%)
Required0 (0.0%)
Privileges Required
Low4 (80.0%)
High0 (0.0%)
None0 (0.0%)
Unknown1 (20.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sddm Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sddm Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sddm Project's Products

View all 2 CNAs →

Top CWEs