cbcvebase.
CVE-2022-32278
published 2022-06-13

CVE-2022-32278: XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.

PriorityP345high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.51%
71.9th percentile
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianexo< exo 4.16.4-1 (bookworm)exo 4.16.4-1 (bookworm)
xfceexo< 4.16.44.16.4
xfceexo>= 0 < 4.16.0-1+deb11u14.16.0-1+deb11u1
xfceexo>= 0 < 4.16.4-14.16.4-1
xfceexo>= 0 < 4.16.4-14.16.4-1
xfceexo>= 0 < 4.16.4-14.16.4-1
xfceexo>= 4.17.0 < 4.17.24.17.2

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.