Back to Database
Status published
High
CVE-2022-32278
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open...
Vulnerability Description
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-32278
Credits & Attribution
No credits recorded in the NVD database.
References
More from xfce
View All →CVE-2022-45062
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there...
Unknown
0
CVE-2021-32563
An issue was discovered in Thunar before 4.16.7 and 4.17.x...
Critical
9.8
CVE-2018-18398
Xfce Thunar 1.6.15, when Xfce 4.12 is used, mishandles the...
Medium
4.7
CVE-2009-4996
Xfce4-session 4.5.91 in Xfce does not lock the screen when...
High
7.2
CVE-2007-6532
Double free vulnerability in the Widget Library (libxfcegui4) in Xfce...
Critical
10
Affected Vendor
xfce
View all reports →Affected Software
exo, debian linux
Vulnerable Versions:
0, 4.17.0, 9.0, 10.0, 11.0
Timeline
Official Publish:
June 13th, 2022
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.