Freedesktop xdg-utils 1.0

CPE Details

Freedesktop xdg-utils 1.0
1.0
2019-09-27
15h04 +00:00
2019-09-27
15h04 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:freedesktop:xdg-utils:1.0:*:*:*:*:*:*:*

Informations

Vendor

freedesktop

Product

xdg-utils

Version

1.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2017-18266 2018-05-10 12h00 +00:00 The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by %s in this environment variable.
8.8
High
CVE-2009-0068 2009-01-07 18h00 +00:00 Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.
6.8