Gnome
gnome
349 CVEs • 102 products
Products (102)
Click to collapseToggle
Products (102)
Click to collapse
CVEs (349)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrect use of libxml2 API. The vendor forgot to call 'g_free()' to release the return...Show more |
3Debian GnomeNetapp3Active Iq Unified Manager Debian LinuxGlibJun 17, 2026 Aug 23, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition. |
3Debian FedoraprojectGnome3Debian Linux FedoraGdk PixbufJun 17, 2026 Jul 24, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable an...Show more |
Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privilege permissions, may take advantage of the way CAP_SYS_NICE is currently implemented and...Show more |
3Debian FedoraprojectGnome3Debian Linux EpiphanyFedoraJun 17, 2026 Apr 20, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for...Show more |
A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that leverage Caribou as an input mechanism. The highest threat from this vulne...Show more |
GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename. |
2Centos Gnome2Gnome Shell StreamJun 17, 2026 Feb 18, 2022 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enabled. This flaw allows a physical attacke...Show more |
3Debian FedoraprojectGnome3Debian Linux FedoraGdkpixbufJun 17, 2026 Jan 12, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12. |
2Debian Gnome2Debian Linux EpiphanyJun 17, 2026 Dec 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page. |
2Debian Gnome2Debian Linux EpiphanyJun 17, 2026 Dec 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title. |
2Debian Gnome2Debian Linux EpiphanyJun 17, 2026 Dec 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js. |
2Debian Gnome2Debian Linux EpiphanyJun 17, 2026 Dec 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Vis...Show more |
2Debian Gnome2Debian Linux GriloJun 17, 2026 Aug 22, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-2001...Show more |
In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE...Show more |
2Fedoraproject Gnome2Fedora LibzapojitJun 17, 2026 Aug 22, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-201...Show more |
2Fedoraproject Gnome2Fedora LibgdaJun 17, 2026 Aug 22, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-201...Show more |
2Fedoraproject Gnome2Fedora LibgfbgraphJun 17, 2026 Aug 22, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-...Show more |
GNOME gThumb before 3.10.1 allows an application crash via a malformed JPEG image. |
2Fedoraproject Gnome2Fedora Gdk PixbufJun 17, 2026 May 28, 2021 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potenti...Show more |