Gnome
gnome
349 CVEs • 102 products
Products (102)
Click to collapseToggle
Products (102)
Click to collapse
CVEs (349)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Gnome Ytnef Project2Evolution YtnefNov 21, 2024 May 26, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitr...Show more |
3Fedoraproject GnomeRedhat4Enterprise Linux FedoraNetworkmanager+1 moreJun 17, 2026 May 26, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability. |
libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of...Show more |
An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against loca...Show more |
2Fedoraproject Gnome2Fedora File RollerJun 17, 2026 Apr 7, 2021 N/A· v4 3.9 LOW· v3 2.6 LOW· v2 fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in cer...Show more |
2Fedoraproject Gnome2Fedora Gnome AutoarJun 17, 2026 Mar 17, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink i...Show more |
4Broadcom DebianFedoraproject+1 more4Brocade Fabric Operating System Firmware Debian LinuxFedora+1 moreJun 17, 2026 Mar 11, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlin...Show more |
5Broadcom DebianFedoraproject+2 more7Active Iq Unified Manager Brocade Fabric Operating System FirmwareCloud Backup+4 moreJun 17, 2026 Feb 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could poten...Show more |
5Broadcom DebianFedoraproject+2 more7Active Iq Unified Manager Brocade Fabric Operating System FirmwareCloud Backup+4 moreJun 17, 2026 Feb 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing u...Show more |
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings Use...Show more |
2Fedoraproject Gnome2Fedora Gnome AutoarJun 17, 2026 Feb 5, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink...Show more |
GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dis...Show more |
1Gnome 1Gnome Display Manager Jun 17, 2026 Dec 28, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session witho...Show more |
3Canonical FedoraprojectGnome3Fedora Gdk PixbufUbuntu LinuxJun 17, 2026 Dec 26, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The...Show more |
GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's position is "Realistically this is not a security issue. The standard pattern...Show more |
1Gnome 1Gnome Display Manager Jun 17, 2026 Nov 10, 2020 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 gdm3 versions before 3.36.2 or 3.38.2 would start gnome-initial-setup if gdm3 can't contact the accountservice service via dbus in a timely manner; on Ubuntu (and potentially derivatives) this could be be chained with an...Show more |
2Fedoraproject Gnome2Fedora GearyJun 17, 2026 Aug 26, 2020 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system...Show more |
4Canonical DebianGnome+1 more4Debian Linux Gnome ShellLeap+1 moreJun 17, 2026 Aug 11, 2020 N/A· v4 4.3 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had dec...Show more |
2Gnome Opensuse3Backports Sle BalsaLeapJun 17, 2026 Jul 29, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c. |
2Debian Gnome2Debian Linux Evolution Data ServerJun 17, 2026 Jul 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related t...Show more |