Known Vulnerabilities for products from Xfce
Listed below are 8 of the newest known vulnerabilities associated with the vendor "Xfce".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-45062 json | In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-hel... | 9.8 - CRITICAL | 2022-11-09 | 2023-11-07 |
| CVE-2022-32278 json | XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled F... | 8.8 - HIGH | 2022-06-13 | 2022-07-08 |
| CVE-2021-32563 json | An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line a... | 9.8 - CRITICAL | 2021-05-11 | 2023-02-28 |
| CVE-2018-18398 json | Xfce Thunar 1.6.15, when Xfce 4.12 is used, mishandles the IBus-Unikey input method for file searches within File Manager, le... | 4.7 - MEDIUM | 2018-10-19 | 2018-12-21 |
| CVE-2011-1588 json | Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error. | 7.8 - HIGH | 2019-11-14 | 2020-08-18 |
| CVE-2009-4996 json | Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make it ea... | Not Provided | 2010-09-07 | 2026-04-29 |
| CVE-2007-6532 json | Double free vulnerability in the Widget Library (libxfcegui4) in Xfce before 4.4.2 might allow remote attackers to execute ar... | Not Provided | 2008-01-09 | 2026-04-23 |
| CVE-2007-6531 json | Stack-based buffer overflow in the Panel (xfce4-panel) component in Xfce before 4.4.2 might allow remote attackers to execute... | Not Provided | 2008-01-09 | 2026-04-23 |