← Back

Gtk

gtk

Vendor: Gnome • 15 CVEs

CVEs (15)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Gnome
XchatXchat Wdk
3Gtk
XchatXchat Wdk
Nov 21, 2024
Feb 21, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 li...Show more
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 line from server containing characters outside of the Basic Multilingual Plane (BMP).Show less
3Canonical
GnomeLinuxmint
3Gtk
Linux MintUbuntu
May 6, 2026
Jan 16, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.
1Gnome
1Gtk
Apr 29, 2026
Sep 6, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan horse uxtheme.dll file in the current working directory, a different v...Show more
Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan horse uxtheme.dll file in the current working directory, a different vulnerability than CVE-2010-4831.Show less
1Gnome
1Gtk
Apr 29, 2026
Sep 6, 2011
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Untrusted search path vulnerability in gdk/win32/gdkinput-win32.c in GTK+ before 2.21.8 allows local users to gain privileges via a Trojan horse Wintab32.dll file in the current working directory.
1Gnome
2Gtk
Screensaver
Apr 29, 2026
Mar 19, 2010
N/A· v4
N/A· v3
6.2 MEDIUM· v2
gdk/gdkwindow.c in GTK+ before 2.18.5, as used in gnome-screensaver before 2.28.1, performs implicit paints on windows of type GDK_WINDOW_FOREIGN, which triggers an X error in certain circumstances and consequently allow...Show more
gdk/gdkwindow.c in GTK+ before 2.18.5, as used in gnome-screensaver before 2.28.1, performs implicit paints on windows of type GDK_WINDOW_FOREIGN, which triggers an X error in certain circumstances and consequently allows physically proximate attackers to bypass screen locking and access an unattended workstation by pressing the Enter key many times.Show less
1Gnome
1Gtk
Apr 23, 2026
Jan 24, 2007
N/A· v4
N/A· v3
2.1 LOW· v2
The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image file.
1Gnome
2Gdkpixbuf
Gtk
Apr 16, 2026
Nov 18, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a differ...Show more
Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a different vulnerability than CVE-2005-3186.Show less
1Gnome
2Gdkpixbuf
Gtk
Apr 16, 2026
Nov 18, 2005
N/A· v4
N/A· v3
7.8 HIGH· v2
io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.
1Gnome
1Gtk
Apr 16, 2026
May 2, 2005
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.
1Gnome
1Gtk
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.
1Gnome
2Gdkpixbuf
Gtk
Apr 16, 2026
Oct 20, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted ICO file.
1Gnome
2Gdkpixbuf
Gtk
Apr 16, 2026
Oct 20, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color...Show more
Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).Show less
1Gnome
2Gdkpixbuf
Gtk
Apr 16, 2026
Oct 20, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp va...Show more
Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).Show less
1Gnome
2Gdkpixbuf
Gtk
Apr 16, 2026
Oct 20, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted BMP file.
1Gnome
1Gtk
Apr 16, 2026
Feb 12, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.