cbcvebase.
CVE-2022-45062
published 2022-11-09

CVE-2022-45062: In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.

PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.41%
69.6th percentile
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianxfce4-settings< xfce4-settings 4.16.4-1 (bookworm)xfce4-settings 4.16.4-1 (bookworm)
fedoraprojectfedora
xfcexfce4-settings< 4.16.44.16.4
xfcexfce4-settings
xfcexfce4-settings>= 0 < 4.16.0-1+deb11u14.16.0-1+deb11u1
xfcexfce4-settings>= 0 < 4.16.4-14.16.4-1
xfcexfce4-settings>= 0 < 4.16.4-14.16.4-1
xfcexfce4-settings>= 0 < 4.16.4-14.16.4-1

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.