← Back

Gnome

gnome

349 CVEs • 102 products

Products (102)

Click to collapse
Toggle
Glib
glib
Libsoup
libsoup
Evolution
evolution
Gdk Pixbuf
gdk-pixbuf
Gdm
gdm
Gtk
gtk
Epiphany
epiphany
Gdkpixbuf
gdkpixbuf
Screensaver
screensaver
Gnome Shell
gnome-shell
Librsvg
librsvg
Evince
evince
Pango
pango
Gpdf
gpdf
Libcroco
libcroco
Gvfs
gvfs
Gnome Keyring
gnome-keyring
Nautilus
nautilus
Balsa
balsa
Gnumeric
gnumeric
Yelp
yelp
Libgsf
libgsf
Gtk Vnc
gtk-vnc
Libgxps
libgxps
Gthumb
gthumb
File Roller
file-roller
Localsearch
localsearch
Eog
eog
Gtkhtml
gtkhtml
Gedit
gedit
Rhythmbox
rhythmbox
Power Manager
power_manager
Empathy
empathy
Libsocialweb
libsocialweb
Gcab
gcab
Shotwell
shotwell
Gnome Autoar
gnome-autoar
Esound
esound
Gnorpm
gnorpm
Bonobo
bonobo
Gnome Lokkit
gnome-lokkit
Batalla Naval
batalla_naval
Libvte4
libvte4
Libzvt2
libzvt2
Libgda2
libgda2
Dhcdbd
dhcdbd
Gconf
gconf
Ekiga
ekiga
Gnome Vfs
gnome-vfs
Gnome
gnome
Vinagre
vinagre
Libpeas
libpeas
Gmime
gmime
Tomboy
tomboy
Libgdata
libgdata
At Spi2 Atk
at-spi2-atk
Vala
vala
Byzanz
byzanz
Eye Of Gnome
eye_of_gnome
Gnome Session
gnome-session
Librest
librest
Seahorse
seahorse
Gnome Desktop
gnome-desktop
Evolution Ews
evolution-ews
Dia
dia
Orca
orca
Geary
geary
Gupnp
gupnp
Libgrss
libgrss
Libgfbgraph
libgfbgraph
Libgda
libgda
Libzapojit
libzapojit
Evolution Rss
evolution-rss
Grilo
grilo
Ocrfeeder
ocrfeeder
Caribou
caribou
Anjuta
anjuta
Tracker Miners
tracker_miners
Glade
glade
Gnome Maps
gnome-maps

CVEs (349)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
DebianFedoraproject+1 more
4Debian Linux
Evolution Data ServerFedora+1 more
Jun 17, 2026
Jul 17, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response...Show more
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."Show less
2Fedoraproject
Gnome
2Fedora
Networkmanager
Jun 17, 2026
Jun 8, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the...Show more
It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made insecurely.Show less
5Broadcom
CanonicalFedoraproject+2 more
6Balsa
Cloud BackupFabric Operating System+3 more
Jun 17, 2026
May 28, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in...Show more
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications that fail to provide the server identity, including Balsa before 2.5.11 and 2.6.x before 2.6.1, accept a TLS certificate if the certificate is valid for any host.Show less
1Gnome
1Libcroco
Jun 17, 2026
May 12, 2020
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.
1Gnome
1Evolution
Jun 17, 2026
Apr 17, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or direct...Show more
An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email message without showing a warning to the user, as demonstrated by an attach=. value.Show less
3Canonical
DebianGnome
3Debian Linux
File RollerUbuntu Linux
Jun 17, 2026
Apr 13, 2020
N/A· v4
3.9 LOW· v3
3.3 LOW· v2
fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction...Show more
fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.Show less
3Debian
GnomeLinuxmint
3Debian Linux
GthumbPix
Jun 17, 2026
Mar 16, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and...Show more
A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.Show less
2Debian
Gnome
2Debian Linux
Networkmanager
Nov 21, 2024
Mar 10, 2020
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.
3Gnome
XchatXchat Wdk
3Gtk
XchatXchat Wdk
Nov 21, 2024
Feb 21, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 li...Show more
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 line from server containing characters outside of the Basic Multilingual Plane (BMP).Show less
2Gnome
Redhat
5Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+2 more
Nov 21, 2024
Feb 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which mig...Show more
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.Show less
6Canonical
DebianFedoraproject+3 more
6Active Iq Unified Manager
Debian LinuxFedora+3 more
Jun 17, 2026
Feb 2, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of fina...Show more
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.Show less
3Gnome
OpensuseSuse
4Linux Enterprise Desktop
Linux Enterprise ServerNetworkmanager+1 more
Nov 21, 2024
Jan 27, 2020
N/A· v4
6.8 MEDIUM· v3
3.2 LOW· v2
NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.
2Fedoraproject
Gnome
2Fedora
Glib
Jun 17, 2026
Jan 9, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is...Show more
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.Show less
4Canonical
DebianGnome+1 more
4Debian Linux
NetworkmanagerOpensuse+1 more
Nov 21, 2024
Dec 26, 2019
N/A· v4
4.4 MEDIUM· v3
3.3 LOW· v2
In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.
2Debian
Gnome
2Debian Linux
Gnome Keyring
Nov 21, 2024
Dec 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function
2Debian
Gnome
2Debian Linux
Orca
Nov 21, 2024
Dec 11, 2019
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
Orca has arbitrary code execution due to insecure Python module load
3Fedoraproject
GnomeOpensuse
3Dia
FedoraLeap
Jun 17, 2026
Nov 29, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thum...Show more
When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thumbnailer service, this output will usually be written to disk via the system's logging facility (potentially with elevated privileges), thus filling up the disk and eventually rendering the system unusable. (The filename can be for a nonexistent file.) NOTE: this does not affect an upstream release, but affects certain Linux distribution packages with version numbers such as 0.97.3.Show less
1Gnome
1Gnome Font Viewer
Jun 17, 2026
Nov 27, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing a TTF font file that lacks a name section (due to a g_strconcat call that returns NULL).
1Gnome
1Evolution Data Server3
Nov 21, 2024
Nov 25, 2019
N/A· v4
7.3 HIGH· v3
4.3 MEDIUM· v2
evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could us...Show more
evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could use this flaw to obtain login credentials of the victim.Show less
2Fedoraproject
Gnome
2Fedora
Gnome System Log
Nov 21, 2024
Nov 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
gnome-system-log polkit policy allows arbitrary files on the system to be read