Gnome
gnome
349 CVEs • 102 products
Products (102)
Click to collapseToggle
Products (102)
Click to collapse
CVEs (349)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Gnome Redhat2Enterprise Linux LibsoupJun 17, 2026 Mar 17, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP h...Show more |
A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required incrementing nonce-count (nc) attribute. T...Show more |
2Gnome Redhat2Enterprise Linux LibsoupJun 17, 2026 Feb 13, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build confi...Show more |
2Gnome Redhat2Enterprise Linux LibsoupJun 17, 2026 Feb 3, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malform...Show more |
2Gnome Redhat2Enterprise Linux LibsoupJun 17, 2026 Jan 28, 2026 N/A· v4 5.8 MEDIUM· v3 N/A· v2 A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remo...Show more |
2Gnome Redhat2Enterprise Linux LibsoupJun 17, 2026 Jan 28, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verb...Show more |
2Gnome Redhat2Enterprise Linux LibsoupJun 17, 2026 Jan 27, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input u...Show more |
2Gnome Redhat3Enterprise Linux GlibOpenshiftJul 13, 2026 Dec 11, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious fil...Show more |
2Gnome Redhat2Enterprise Linux GlibJul 13, 2026 Dec 10, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when pr...Show more |
2Gnome Redhat29Ceph Storage Codeready Linux BuilderCodeready Linux Builder For Arm64+26 moreJun 30, 2026 Nov 26, 2025 N/A· v4 7.7 HIGH· v3 N/A· v2 A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable character...Show more |
A flaw was found in GLib. A denial of service on Windows platforms may occur if an application attempts to spawn a program using long command lines. |
A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number...Show more |
A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB files, leading to incorrect memory allocations. This issue causes the ap...Show more |
A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the syste...Show more |
2Canonical Gnome2Control Center Ubuntu LinuxJun 17, 2026 Apr 15, 2025 N/A· v4 4.9 MEDIUM· v3 N/A· v2 In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed...Show more |
3Debian GnomeRedhat21Codeready Linux Builder Codeready Linux Builder For Arm64Codeready Linux Builder For Arm64 Eus+18 moreJun 29, 2026 Apr 3, 2025 N/A· v4 7.4 HIGH· v3 N/A· v2 A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an ex...Show more |
2Gnome Redhat21Codeready Linux Builder Codeready Linux Builder For Arm64Codeready Linux Builder For Arm64 Eus+18 moreJun 30, 2026 Apr 3, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted...Show more |
2Canonical Gnome2Gnome Remote Desktop Ubuntu LinuxJun 17, 2026 Jan 31, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default. |
A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbitrary code. |
3Debian GnomeNetapp4Active Iq Unified Manager Debian LinuxGlib+1 moreJun 17, 2026 Nov 11, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character. |