Gnome
gnome
349 CVEs • 102 products
Products (102)
Click to collapseToggle
Products (102)
Click to collapse
CVEs (349)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via an odd number of elements in a coordinate pa...Show more |
2Fedoraproject Gnome2Fedora Gnome Display ManagerMay 6, 2026 Nov 24, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the Escape key. |
4Canonical GnomeOracle+1 more9Linux Linux Enterprise DebuginfoLinux Enterprise Desktop+6 moreMay 6, 2026 Nov 17, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message, a different vulnerability than CVE-2015-8215. |
3Canonical GnomeOpensuse3Gdk Pixbuf OpensuseUbuntu LinuxMay 6, 2026 Oct 26, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in the pixops_scale_nearest function in pixops/pixops.c in gdk-pixbuf before 2.32.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a craf...Show more |
io-tga.c in gdk-pixbuf before 2.32.0 uses heap memory after its allocation failed, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) and possibly execute arbitr...Show more |
5Canonical FedoraprojectGnome+2 more5Fedora Gdk PixbufOpensuse+2 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other produ...Show more |
The GIF encoder in Byzanz allows remote attackers to cause a denial of service (out-of-bounds heap write and crash) or possibly execute arbitrary code via a crafted Byzanz debug data recording (ByzanzRecording file) to t...Show more |
The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-dependent attackers to cause a denial of service (crash) or possibly execute...Show more |
3Canonical GnomeLinuxmint3Gtk Linux MintUbuntuMay 6, 2026 Jan 16, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button. |
Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder.c in gcab 0.4 allows remote attackers to write to arbitrary files via crafted path in a CAB file, as demonstrated by "\tmp\moo....Show more |
2Gnome Redhat5Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+2 moreMay 6, 2026 Dec 25, 2014 N/A· v4 N/A· v3 7.2 HIGH· v2 GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary comma...Show more |
3Gnome OpensuseOracle3Gnome Terminal OpensuseSolarisMay 6, 2026 May 21, 2014 N/A· v4 N/A· v3 3.5 LOW· v2 The "insert-blank-characters" capability in caps.c in gnome-terminal (vte) before 0.28.1 allows remote authenticated users to cause a denial of service (CPU and memory consumption and crash) via a crafted file, as demons...Show more |
GNOME Display Manager (gdm) 3.4.1 and earlier, when disable-user-list is set to true, allows local users to cause a denial of service (unable to login) by pressing the cancel button after entering a user name. |
The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Enter a Command" dialog, which allows physically proximate attackers to execute arbitrary commands by l...Show more |
js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with the keyboard focus on the Activities sear...Show more |
Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a...Show more |
GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) is...Show more |
GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/. |
2Canonical Gnome2Gnome Online Accounts Ubuntu LinuxApr 29, 2026 Apr 2, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attacke...Show more |
2Canonical Gnome2Gnome Online Accounts Ubuntu LinuxApr 29, 2026 Apr 2, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle...Show more |