Freedesktop has 5 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 5.5 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-189 (3) and CWE-190 (3). Most affected products: Poppler (4), polkit (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.5
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
CVE-2026-93313Medium· 6.3A vulnerability was found in Freedesktop Poppler 26.07.047CVE-2026-93314Medium· 6.3A vulnerability was determined in Freedesktop Poppler 26.07.035CVE-2026-4897Medium· 5.5A flaw was found in polkit30CVE-2026-93312Medium· 4.3A flaw has been found in Freedesktop Poppler 26.07.024CVE-2026-93311Medium· 4.3A vulnerability was detected in Freedesktop Poppler 26.07.024
Freedesktop vulnerabilities
CVEs affecting Freedesktop, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-93313Medium· 6.3PoCA vulnerability was found in Freedesktop Poppler 26.07.0
A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be ini…
CVE-2026-93314Medium· 6.3A vulnerability was determined in Freedesktop Poppler 26.07.0
A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. The attac…
CVE-2026-93312Medium· 4.3A flaw has been found in Freedesktop Poppler 26.07.0
A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The…
CVE-2026-93311Medium· 4.3A vulnerability was detected in Freedesktop Poppler 26.07.0
A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the argument BitsPerSampl…
CVE-2026-4897Medium· 5.5A flaw was found in polkit
A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory…