VYPR
Vendor

Xdg Utils

Products
3
CVEs
3
Across products
5
Status
Private

Products

3

Recent CVEs

3
  • CVE-2020-27748MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically…

  • CVE-2025-52968LowJun 23, 2025
    risk 0.18cvss 2.7epss 0.00

    xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (For example, xdg-open could be modified to, by default, associate x-scheme-handler/https with the execution of a browser with command-line options that arrange…

  • CVE-2008-0386Feb 4, 2008
    risk 0.00cvss epss 0.03

    Xdg-utils 1.0.2 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URL argument to (1) xdg-open or (2) xdg-email.