High severity8.8NVD Advisory· Published Jun 13, 2022· Updated Jun 17, 2026
CVE-2022-32278
CVE-2022-32278
Description
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6Patches
Vulnerability mechanics
References
3- gitlab.xfce.org/xfce/exo/-/commit/c71c04ff5882b2866a0d8506fb460d4ef796de9fnvdPatchVendor Advisory
- lists.debian.org/debian-lts-announce/2022/06/msg00018.htmlnvdMailing ListThird Party Advisory
- www.debian.org/security/2022/dsa-5164nvdThird Party Advisory
News mentions
0No linked articles in our index yet.