Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Xfce

First CVE: Jan 9, 2008Active for: 19 yearsTotal CVEs: 8

Xfce is a lightweight desktop environment and window manager widely deployed across Linux distributions, with vulnerabilities concentrated in its core components including the file manager Thunar, library exo, and system settings utilities. The exposure skews toward serious outcomes, with a meaningful share reaching critical severity, and recurs through memory-safety and command-handling weakness classes including buffer overflows, out-of-bounds reads, argument injection, and improper code resource management that are characteristic of native desktop applications. Defenders should prioritize patches for this vendor, particularly where Xfce components are exposed to untrusted input or run with elevated privileges; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Xfce over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 9, 2008
18 years ago
Most Recent CVE
Nov 9, 2022
1,353 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-45062CRITICAL
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
Nov 9, 20229.832NONO
CVE-2021-32563CRITICAL
An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on
May 11, 20219.832NONO
CVE-2007-6532HIGH
Double free vulnerability in the Widget Library (libxfcegui4) in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code via unknown vectors related to the "cliend
Jan 9, 200810.026NONO
CVE-2011-1588HIGH
Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.
Nov 14, 20197.824NONO
CVE-2022-32278HIGH
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
Jun 13, 20228.822NONO
CVE-2009-4996HIGH
Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an un
Sep 7, 20107.220NONO
CVE-2018-18398MEDIUM
Xfce Thunar 1.6.15, when Xfce 4.12 is used, mishandles the IBus-Unikey input method for file searches within File Manager, leading to an out-of-bounds read and SEGV. This could pot
Oct 19, 20184.718NONO
CVE-2007-6531MEDIUM
Stack-based buffer overflow in the Panel (xfce4-panel) component in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code via Launcher tooltips. NOTE: a second
Jan 9, 20085.016NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
25%
50%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (25.0%)
Network3 (37.5%)
Unknown3 (37.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (50.0%)
High1 (12.5%)
Unknown3 (37.5%)
User Interaction
None3 (37.5%)
Unknown3 (37.5%)
Required2 (25.0%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None4 (50.0%)
Unknown3 (37.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Xfce.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Xfce — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Xfce's Products

View all 2 CNAs →

Top CWEs