Double free vulnerability in the Widget Library (libxfcegui4) in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code via unknown vectors related to the "cliend id, program name and working directory in session management."
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade libxfce4guiUpgrade xfce4-panel | Dec 10, 2025 | Jan 22, 2008 |
| Gentoo Linux | — | Upgrade xfce-base/xfce4-panel.Upgrade xfce-base/libxfcegui4. | Oct 30, 2017 | Jan 9, 2008 |
| Suse | — | Upgrade suse-releaseUpgrade libxfcegui4-develUpgrade xfce4-panel-develUpgrade libxfcegui4Upgrade xfce4-panel | Dec 12, 2013 | Jan 9, 2008 |
| Ubuntu | — | Upgrade libxfcegui4 | Nov 19, 2024 | Jan 9, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub