Xfce is a lightweight desktop environment and window manager widely deployed across Linux distributions, with vulnerabilities concentrated in its core components including the file manager Thunar, library exo, and system settings utilities. The exposure skews toward serious outcomes, with a meaningful share reaching critical severity, and recurs through memory-safety and command-handling weakness classes including buffer overflows, out-of-bounds reads, argument injection, and improper code resource management that are characteristic of native desktop applications. Defenders should prioritize patches for this vendor, particularly where Xfce components are exposed to untrusted input or run with elevated privileges; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xfce over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45062CRITICAL In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper. | Nov 9, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-32563CRITICAL An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on | May 11, 2021 | 9.8 | 32 | NO | NO |
CVE-2007-6532HIGH Double free vulnerability in the Widget Library (libxfcegui4) in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code via unknown vectors related to the "cliend | Jan 9, 2008 | 10.0 | 26 | NO | NO |
CVE-2011-1588HIGH Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error. | Nov 14, 2019 | 7.8 | 24 | NO | NO |
CVE-2022-32278HIGH XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server. | Jun 13, 2022 | 8.8 | 22 | NO | NO |
CVE-2009-4996HIGH Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an un | Sep 7, 2010 | 7.2 | 20 | NO | NO |
CVE-2018-18398MEDIUM Xfce Thunar 1.6.15, when Xfce 4.12 is used, mishandles the IBus-Unikey input method for file searches within File Manager, leading to an out-of-bounds read and SEGV. This could pot | Oct 19, 2018 | 4.7 | 18 | NO | NO |
CVE-2007-6531MEDIUM Stack-based buffer overflow in the Panel (xfce4-panel) component in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code via Launcher tooltips. NOTE: a second | Jan 9, 2008 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xfce.
Media articles that mention a CVE ID that affects a product developed by Xfce — matched by CVE ID, not by vendor name.