Gnome
gnome
349 CVEs • 102 products
Products (102)
Click to collapseToggle
Products (102)
Click to collapse
CVEs (349)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical GnomeOracle3Gnome Keyring Ubuntu LinuxZfs Storage Appliance KitNov 21, 2024 Feb 12, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext. |
2Debian Gnome2Debian Linux EvolutionNov 21, 2024 Feb 11, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment. |
3Canonical GnomeRedhat3Enterprise Linux Gnome Display ManagerUbuntu LinuxJun 17, 2026 Feb 6, 2019 N/A· v4 6.4 MEDIUM· v3 6.9 MEDIUM· v2 A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by selecting the timed login user and waiting for the timer to expire, at which...Show more |
3Canonical GnomeOpensuse3Gnome Shell LeapUbuntu LinuxJun 17, 2026 Feb 6, 2019 N/A· v4 4.3 MEDIUM· v3 4.6 MEDIUM· v2 It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts,...Show more |
6Canonical FedoraprojectGnome+3 more6Epiphany FedoraLeap+3 moreJun 17, 2026 Jan 14, 2019 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is...Show more |
GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that th...Show more |
GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow dialog at an unattended workstation, if the keyring is unlocked. NOTE: this is disputed by a software...Show more |
2Debian Gnome2Debian Linux GthumbNov 21, 2024 Oct 29, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the add_themes_from_dir method in dlg-contact-sheet.c because of two successive calls of g_free, each of which frees the same buffe...Show more |
2Canonical Gnome2Glib Ubuntu LinuxNov 21, 2024 Sep 4, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str(). |
2Canonical Gnome2Glib Ubuntu LinuxNov 21, 2024 Sep 4, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference. |
2Canonical Gnome2Pango Ubuntu LinuxNov 21, 2024 Aug 24, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with inv...Show more |
The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of...Show more |
1Gnome 1Gnome Display Manager Nov 21, 2024 Jul 26, 2018 N/A· v4 6.4 MEDIUM· v3 6.9 MEDIUM· v2 A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as another user' to unlock...Show more |
2Debian Gnome2Debian Linux Network Manager VpncNov 21, 2024 Jul 26, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration dat...Show more |
2Canonical Gnome2Evolution Ubuntu LinuxNov 21, 2024 Jul 20, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will n...Show more |
5Canonical DebianGnome+2 more9Ansible Tower Debian LinuxEnterprise Linux Desktop+6 moreNov 21, 2024 Jul 5, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname. |
addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that is processed by the strcat function. NOT...Show more |
libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via certain window.open and document.write calls. |
2Gnome Webkitgtk2Libsoup WebkitgtkNov 21, 2024 Jun 4, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy sett...Show more |
ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrat...Show more |