← Back

Gnome

gnome

349 CVEs • 102 products

Products (102)

Click to collapse
Toggle
Glib
glib
Libsoup
libsoup
Evolution
evolution
Gdk Pixbuf
gdk-pixbuf
Gdm
gdm
Gtk
gtk
Epiphany
epiphany
Gdkpixbuf
gdkpixbuf
Screensaver
screensaver
Gnome Shell
gnome-shell
Librsvg
librsvg
Evince
evince
Pango
pango
Gpdf
gpdf
Libcroco
libcroco
Gvfs
gvfs
Gnome Keyring
gnome-keyring
Nautilus
nautilus
Balsa
balsa
Gnumeric
gnumeric
Yelp
yelp
Libgsf
libgsf
Gtk Vnc
gtk-vnc
Libgxps
libgxps
Gthumb
gthumb
File Roller
file-roller
Localsearch
localsearch
Eog
eog
Gtkhtml
gtkhtml
Gedit
gedit
Rhythmbox
rhythmbox
Power Manager
power_manager
Empathy
empathy
Libsocialweb
libsocialweb
Gcab
gcab
Shotwell
shotwell
Gnome Autoar
gnome-autoar
Esound
esound
Gnorpm
gnorpm
Bonobo
bonobo
Gnome Lokkit
gnome-lokkit
Batalla Naval
batalla_naval
Libvte4
libvte4
Libzvt2
libzvt2
Libgda2
libgda2
Dhcdbd
dhcdbd
Gconf
gconf
Ekiga
ekiga
Gnome Vfs
gnome-vfs
Gnome
gnome
Vinagre
vinagre
Libpeas
libpeas
Gmime
gmime
Tomboy
tomboy
Libgdata
libgdata
At Spi2 Atk
at-spi2-atk
Vala
vala
Byzanz
byzanz
Eye Of Gnome
eye_of_gnome
Gnome Session
gnome-session
Librest
librest
Seahorse
seahorse
Gnome Desktop
gnome-desktop
Evolution Ews
evolution-ews
Dia
dia
Orca
orca
Geary
geary
Gupnp
gupnp
Libgrss
libgrss
Libgfbgraph
libgfbgraph
Libgda
libgda
Libzapojit
libzapojit
Evolution Rss
evolution-rss
Grilo
grilo
Ocrfeeder
ocrfeeder
Caribou
caribou
Anjuta
anjuta
Tracker Miners
tracker_miners
Glade
glade
Gnome Maps
gnome-maps

CVEs (349)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gnome
1Gdm
Apr 16, 2026
Apr 25, 2006
N/A· v4
N/A· v3
3.7 LOW· v2
Race condition in daemon/slave.c in gdm before 2.14.1 allows local users to gain privileges via a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file.
1Gnome
1Screensaver
Apr 16, 2026
Mar 21, 2006
N/A· v4
N/A· v3
3.7 LOW· v2
gnome screensaver before 2.14, when running on an X server with AllowDeactivateGrabs and AllowClosedownGrabs enabled, allows attackers with physical access to cause the screensaver to crash and access the session via the...Show more
gnome screensaver before 2.14, when running on an X server with AllowDeactivateGrabs and AllowClosedownGrabs enabled, allows attackers with physical access to cause the screensaver to crash and access the session via the Ctl+Alt+Keypad-Multiply keyboard sequence, which removes the grab from gnome.Show less
4Debian
GnomeLibextractor+1 more
4Debian Linux
GpdfLibextractor+1 more
Apr 16, 2026
Mar 15, 2006
N/A· v4
N/A· v3
7.6 HIGH· v2
Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vec...Show more
Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc. NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed. Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.Show less
1Gnome
1Dwarf Http Server
Apr 16, 2026
Mar 13, 2006
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Dwarf HTTP Server 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified error messages.
1Gnome
1Dwarf Http Server
Apr 16, 2026
Mar 13, 2006
N/A· v4
N/A· v3
7.8 HIGH· v2
Dwarf HTTP Server 1.3.2 allows remote attackers to obtain the source code of JSP files via (1) dot, (2) space, (3) slash, or (4) NULL characters in the filename extension of an HTTP request.
1Gnome
1Evolution
Apr 16, 2026
Mar 10, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml.
1Gnome
1Evolution
Apr 16, 2026
Feb 2, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Dispos...Show more
The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to repeatedly crash until the e-mail message is manually removed, possibly due to a buffer overflow, as demonstrated using an XML attachment.Show less
2Gnome
Gtk
2Gdkpixbuf
Gtk+
Apr 16, 2026
Nov 18, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which...Show more
Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which leads to a heap-based buffer overflow.Show less
1Gnome
2Gdkpixbuf
Gtk
Apr 16, 2026
Nov 18, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a differ...Show more
Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a different vulnerability than CVE-2005-3186.Show less
1Gnome
2Gdkpixbuf
Gtk
Apr 16, 2026
Nov 18, 2005
N/A· v4
N/A· v3
7.8 HIGH· v2
io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.
1Gnome
1Libgda2
Apr 16, 2026
Oct 25, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple format string vulnerabilities in the GNOME Data Access library for GNOME2 (libgda2) 1.2.1 and earlier allow attackers to execute arbitrary code.
1Gnome
2Libvte4
Libzvt2
Apr 16, 2026
Oct 5, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
gnome-pty-helper in GNOME libzvt2 and libvte4 allows local users to spoof the logon hostname via a modified DISPLAY environment variable. NOTE: the severity of this issue has been disputed.
1Gnome
1Evolution
Apr 16, 2026
Aug 12, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not pro...Show more
Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab.Show less
1Gnome
1Evolution
Apr 16, 2026
Aug 12, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remot...Show more
Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.Show less
1Gnome
1Networkmanager
Apr 16, 2026
Aug 1, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Format string vulnerability in the nm_info_handler function in Network Manager may allow remote attackers to execute arbitrary code via format string specifiers in a Wireless Access Point identifier, which is not properl...Show more
Format string vulnerability in the nm_info_handler function in Network Manager may allow remote attackers to execute arbitrary code via format string specifiers in a Wireless Access Point identifier, which is not properly handled in a syslog call.Show less
1Gnome
1Gedit
Apr 16, 2026
May 20, 2005
N/A· v4
N/A· v3
2.6 LOW· v2
Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename. NOTE: while this issue is triggered on the c...Show more
Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename. NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.Show less
1Gnome
1Gtk
Apr 16, 2026
May 2, 2005
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.
1Gnome
1Gtk
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.
4Gnome
MozillaOmnigroup+1 more
5Camino
EpiphanyMozilla+2 more
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph charact...Show more
The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.Show less
15Ascii
CstexDebian+12 more
22Advanced Linux Environment
CstetexCups+19 more
Apr 16, 2026
Apr 27, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the origin...Show more
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.Show less