CVE-2014-9622: Gentoo Xdg-Utils

Medium severity, CVSS 6.8. EPSS: 3.3% chance of exploitation in the next 30 days.

Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execute arbitrary code via the URL argument to xdg-open.

Affected products

  • Gentoo Xdg-Utils: version 1.1.0 only

Published 2015-01-21. Last modified 2026-06-17.