← Back

Gnome

gnome

353 CVEs • 102 products

Products (102)

Click to collapse
Toggle
Glib
glib
Libsoup
libsoup
Evolution
evolution
Gdk Pixbuf
gdk-pixbuf
Gdm
gdm
Gtk
gtk
Epiphany
epiphany
Gdkpixbuf
gdkpixbuf
Screensaver
screensaver
Gnome Shell
gnome-shell
Librsvg
librsvg
Evince
evince
Pango
pango
Gpdf
gpdf
Libcroco
libcroco
Gvfs
gvfs
Gnome Keyring
gnome-keyring
Nautilus
nautilus
Balsa
balsa
Gnumeric
gnumeric
Yelp
yelp
Libgsf
libgsf
Gtk Vnc
gtk-vnc
Libgxps
libgxps
Gthumb
gthumb
File Roller
file-roller
Localsearch
localsearch
Eog
eog
Gtkhtml
gtkhtml
Gedit
gedit
Rhythmbox
rhythmbox
Power Manager
power_manager
Empathy
empathy
Libsocialweb
libsocialweb
Gcab
gcab
Shotwell
shotwell
Gnome Autoar
gnome-autoar
Esound
esound
Gnorpm
gnorpm
Bonobo
bonobo
Gnome Lokkit
gnome-lokkit
Batalla Naval
batalla_naval
Libvte4
libvte4
Libzvt2
libzvt2
Libgda2
libgda2
Dhcdbd
dhcdbd
Gconf
gconf
Ekiga
ekiga
Gnome Vfs
gnome-vfs
Gnome
gnome
Vinagre
vinagre
Libpeas
libpeas
Gmime
gmime
Tomboy
tomboy
Libgdata
libgdata
At Spi2 Atk
at-spi2-atk
Vala
vala
Byzanz
byzanz
Eye Of Gnome
eye_of_gnome
Gnome Session
gnome-session
Librest
librest
Seahorse
seahorse
Gnome Desktop
gnome-desktop
Evolution Ews
evolution-ews
Dia
dia
Orca
orca
Geary
geary
Gupnp
gupnp
Libgrss
libgrss
Libgfbgraph
libgfbgraph
Libgda
libgda
Libzapojit
libzapojit
Evolution Rss
evolution-rss
Grilo
grilo
Ocrfeeder
ocrfeeder
Caribou
caribou
Anjuta
anjuta
Tracker Miners
tracker_miners
Glade
glade
Gnome Maps
gnome-maps

CVEs (353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Gnome
2Fedora
Geary
Jun 17, 2026
Aug 26, 2020
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system...Show more
GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system-provided PKCS#11 store. This allows a meddler in the middle to present a different invalid certificate to intercept incoming and outgoing mail.Show less
4Canonical
DebianGnome+1 more
4Debian Linux
Gnome ShellLeap+1 more
Jun 17, 2026
Aug 11, 2020
N/A· v4
4.3 MEDIUM· v3
1.9 LOW· v2
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had dec...Show more
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment upon a logout. (If the password were never shown in cleartext, only the password length is revealed.)Show less
2Gnome
Opensuse
3Backports Sle
BalsaLeap
Jun 17, 2026
Jul 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c.
2Debian
Gnome
2Debian Linux
Evolution Data Server
Jun 17, 2026
Jul 29, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related t...Show more
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
Evolution Data ServerFedora+1 more
Jun 17, 2026
Jul 17, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response...Show more
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."Show less
2Fedoraproject
Gnome
2Fedora
Networkmanager
Jun 17, 2026
Jun 8, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the...Show more
It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made insecurely.Show less
5Broadcom
CanonicalFedoraproject+2 more
6Balsa
Cloud BackupFabric Operating System+3 more
Jun 17, 2026
May 28, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in...Show more
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications that fail to provide the server identity, including Balsa before 2.5.11 and 2.6.x before 2.6.1, accept a TLS certificate if the certificate is valid for any host.Show less
1Gnome
1Libcroco
Jun 17, 2026
May 12, 2020
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.
1Gnome
1Evolution
Jun 17, 2026
Apr 17, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or direct...Show more
An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email message without showing a warning to the user, as demonstrated by an attach=. value.Show less
3Canonical
DebianGnome
3Debian Linux
File RollerUbuntu Linux
Jun 17, 2026
Apr 13, 2020
N/A· v4
3.9 LOW· v3
3.3 LOW· v2
fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction...Show more
fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.Show less
3Debian
GnomeLinuxmint
3Debian Linux
GthumbPix
Jun 17, 2026
Mar 16, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and...Show more
A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.Show less
2Debian
Gnome
2Debian Linux
Networkmanager
Nov 21, 2024
Mar 10, 2020
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.
3Gnome
XchatXchat Wdk
3Gtk
XchatXchat Wdk
Nov 21, 2024
Feb 21, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 li...Show more
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 line from server containing characters outside of the Basic Multilingual Plane (BMP).Show less
2Gnome
Redhat
5Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+2 more
Nov 21, 2024
Feb 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which mig...Show more
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.Show less
6Canonical
DebianFedoraproject+3 more
6Active Iq Unified Manager
Debian LinuxFedora+3 more
Jun 17, 2026
Feb 2, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of fina...Show more
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.Show less
3Gnome
OpensuseSuse
4Linux Enterprise Desktop
Linux Enterprise ServerNetworkmanager+1 more
Nov 21, 2024
Jan 27, 2020
N/A· v4
6.8 MEDIUM· v3
3.2 LOW· v2
NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.
2Fedoraproject
Gnome
2Fedora
Glib
Jun 17, 2026
Jan 9, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is...Show more
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.Show less
4Canonical
DebianGnome+1 more
4Debian Linux
NetworkmanagerOpensuse+1 more
Nov 21, 2024
Dec 26, 2019
N/A· v4
4.4 MEDIUM· v3
3.3 LOW· v2
In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.
2Debian
Gnome
2Debian Linux
Gnome Keyring
Nov 21, 2024
Dec 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function
2Debian
Gnome
2Debian Linux
Orca
Nov 21, 2024
Dec 11, 2019
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
Orca has arbitrary code execution due to insecure Python module load