Gnome
gnome
349 CVEs • 102 products
Products (102)
Click to collapseToggle
Products (102)
Click to collapse
CVEs (349)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFedoraproject+1 more4Debian Linux Evolution Data ServerFedora+1 moreJun 17, 2026 Jul 17, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response...Show more |
2Fedoraproject Gnome2Fedora NetworkmanagerJun 17, 2026 Jun 8, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the...Show more |
5Broadcom CanonicalFedoraproject+2 more6Balsa Cloud BackupFabric Operating System+3 moreJun 17, 2026 May 28, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in...Show more |
libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption. |
An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or direct...Show more |
3Canonical DebianGnome3Debian Linux File RollerUbuntu LinuxJun 17, 2026 Apr 13, 2020 N/A· v4 3.9 LOW· v3 3.3 LOW· v2 fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction...Show more |
3Debian GnomeLinuxmint3Debian Linux GthumbPixJun 17, 2026 Mar 16, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and...Show more |
2Debian Gnome2Debian Linux NetworkmanagerNov 21, 2024 Mar 10, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection. |
3Gnome XchatXchat Wdk3Gtk XchatXchat WdkNov 21, 2024 Feb 21, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 li...Show more |
2Gnome Redhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreNov 21, 2024 Feb 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which mig...Show more |
6Canonical DebianFedoraproject+3 more6Active Iq Unified Manager Debian LinuxFedora+3 moreJun 17, 2026 Feb 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of fina...Show more |
3Gnome OpensuseSuse4Linux Enterprise Desktop Linux Enterprise ServerNetworkmanager+1 moreNov 21, 2024 Jan 27, 2020 N/A· v4 6.8 MEDIUM· v3 3.2 LOW· v2 NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used. |
2Fedoraproject Gnome2Fedora GlibJun 17, 2026 Jan 9, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is...Show more |
4Canonical DebianGnome+1 more4Debian Linux NetworkmanagerOpensuse+1 moreNov 21, 2024 Dec 26, 2019 N/A· v4 4.4 MEDIUM· v3 3.3 LOW· v2 In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network. |
2Debian Gnome2Debian Linux Gnome KeyringNov 21, 2024 Dec 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function |
Orca has arbitrary code execution due to insecure Python module load |
3Fedoraproject GnomeOpensuse3Dia FedoraLeapJun 17, 2026 Nov 29, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thum...Show more |
In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing a TTF font file that lacks a name section (due to a g_strconcat call that returns NULL). |
evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could us...Show more |
2Fedoraproject Gnome2Fedora Gnome System LogNov 21, 2024 Nov 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 gnome-system-log polkit policy allows arbitrary files on the system to be read |