CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “freedesktop”

76 vulnerabilities found for “freedesktop”

Page 1 of 4

CVE-2026-26104
MEDIUM5.5

A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations. This weakens the confidentiality guarantees of encrypted storage volumes.

redhat / enterprise_linux+1
Local
Published Feb 25, 2026
Page 1 of 4
CVE-2026-26103
HIGH7.1

A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys and render encrypted volumes inaccessible. Successful exploitation results in a denial-of-service condition through irreversible data loss.

redhat / enterprise_linux+1
Local
Published Feb 25, 2026
CVE-2024-6239
HIGH7.5

A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.

freedesktop / poppler+3
Network
Published Jun 21, 2024
CVE-2022-37051
MEDIUM6.5

An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file.

freedesktop / poppler+1
Network
Published Aug 22, 2023
CVE-2022-37052
MEDIUM6.5

A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.

freedesktop / poppler
Network
Published Aug 22, 2023
CVE-2020-18839
MEDIUM6.5

Buffer Overflow vulnerability in HtmlOutputDev::page in poppler 0.75.0 allows attackers to cause a denial of service.

freedesktop / poppler
Network
Published Aug 22, 2023
CVE-2020-23804
HIGH7.5

Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.

freedesktop / poppler+1
Network
Published Aug 22, 2023
CVE-2022-37050
MEDIUM6.5

In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the incomplete patch of CVE-2018-20662.

freedesktop / poppler+1
Network
Published Aug 22, 2023
CVE-2022-38349
MEDIUM6.5

An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.

freedesktop / poppler
Network
Published Aug 22, 2023
CVE-2020-36023
MEDIUM6.5

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function.

freedesktop / poppler
Network
Published Aug 11, 2023
CVE-2020-36024
MEDIUM5.5

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function.

freedesktop / poppler
Local
Published Aug 11, 2023
CVE-2023-34872
MEDIUM5.5

A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.

freedesktop / poppler
Local
Published Jul 31, 2023
CVE-2022-38784
HIGH7.8

Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2022-38171 in Xpdf.

freedesktop / poppler+5
Local
Published Aug 30, 2022
CVE-2022-38171
HIGH7.8

Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple CoreGraphics).

xpdfreader / xpdf+1
Local
Published Aug 22, 2022
CVE-2022-31782
HIGH7.8

ftbench.c in FreeType Demo Programs through 2.12.1 has a heap-based buffer overflow.

freedesktop / freetype_demo_programs
Local
Published Jun 2, 2022
CVE-2022-27337
MEDIUM6.5

A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

freedesktop / poppler+3
Network
Published May 5, 2022
CVE-2021-30860
HIGH7.8

An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

apple / ipados+14
Local
Published Aug 24, 2021
CVE-2020-35702
HIGH7.8

DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones in late December 2020, not the 20.12.1 release. In this situation, it should NOT be considered a Poppler vulnerability. However, several third-party Open Source projects directly rely on Poppler git clones made at arbitrary times, and therefore the CVE remains useful to users of those projects

freedesktop / poppler
Local
Published Dec 25, 2020
CVE-2020-27778
HIGH7.5

A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service.

freedesktop / poppler+2
Network
Published Dec 3, 2020
CVE-2018-17336
HIGH7.8

UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c, allowing attackers to obtain sensitive information (stack contents), cause a denial of service (memory corruption), or possibly have unspecified other impact via a malformed filesystem label, as demonstrated by %d or %n substrings.

freedesktop / udisks+1
Local
Published Sep 22, 2018