Gnome
gnome
349 CVEs • 102 products
Products (102)
Click to collapseToggle
Products (102)
Click to collapse
CVEs (349)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
169folders AppleBloop+13 more17Airmail EmclientEvolution+14 moreNov 21, 2024 May 16, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. |
2Gnome Redhat5Ansible Tower Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 May 6, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_rea...Show more |
3Gnome OpensuseRedhat6Ansible Tower Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 May 4, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack. |
3Debian GnomeRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Apr 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow resulting in remote code execution. An attacker can send a special HT...Show more |
2Canonical Gnome2Networkmanager Ubuntu LinuxNov 21, 2024 Mar 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DNS queries leaked to local network's DNS servers, while on VPN. This vul...Show more |
2Debian Gnome2Debian Linux LibrsvgNov 21, 2024 Feb 9, 2018 N/A· v4 8.8 HIGH· v3 4.3 MEDIUM· v2 GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can result in the victim's Windows username and NTLM password hash being l...Show more |
5Canonical DebianFedoraproject+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 21, 2024 Jan 12, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file. |
3Canonical DebianGnome3Debian Linux Gdk PixbufUbuntu LinuxNov 21, 2024 Jan 2, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential code execution |
Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91. |
2Debian Gnome2Debian Linux NautilusMay 13, 2026 Sep 20, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .desktop file's Name field ends in .pdf but this file's Exec field launche...Show more |
2Debian Gnome2Debian Linux Gdk PixbufMay 13, 2026 Sep 5, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable integer overflow vulnerability exists in the tiff_image_parse functionality of Gdk-Pixbuf 2.36.6 when compiled with Clang. A specially crafted tiff file can cause a heap-overflow resulting in remote code e...Show more |
2Debian Gnome2Debian Linux Gdk PixbufMay 13, 2026 Sep 5, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable heap overflow vulnerability exists in the gdk_pixbuf__jpeg_image_load_increment functionality of Gdk-Pixbuf 2.36.6. A specially crafted jpeg file can cause a heap overflow resulting in remote code executio...Show more |
libgedit.a in GNOME gedit through 3.22.1 allows remote attackers to cause a denial of service (CPU consumption) via a file that begins with many '\0' characters. |
3Debian GnomeRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Sep 5, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with...Show more |
The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (application crash) via run...Show more |
There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack. |
A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because of incorrect protection against division by zero. |
gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when rendering |
GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfiltration of stored pa...Show more |
Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext transmission |