Skip to main content

Vendor archive

gnome CVEs

Beta · best-effort

359 CVEs tagged to vendor gnome32 Critical, 115 High, 175 Medium, 37 Low, 0 Unrated.

CVE-2010-2387

Published Dec 21, 2012

vicious-extensions/ve-misc.c in GNOME Display Manager (gdm) 2.20.x before 2.20.11, when GDM debug is enabled, logs the user password when it contains invalid UTF8 encoded characte…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-5244

Published Nov 19, 2012

Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other produ…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0433

Published Nov 19, 2012

Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4511

Published Oct 22, 2012

services/flickr/flickr.c in libsocialweb before 0.25.21 automatically connects to Flickr when no Flickr account is set, which might allow remote attackers to obtain sensitive info…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3466

Published Oct 22, 2012

GNOME gnome-keyring 3.4.0 through 3.4.1, when gpg-cache-method is set to "idle" or "timeout," does not properly limit the amount of time a passphrase is cached, which allows attac…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4129

Published Oct 22, 2012

(1) services/twitter/twitter-contact-view.c and (2) services/twitter/twitter-item-view.c in libsocialweb before 0.25.20 automatically connect to Twitter when no Twitter account is…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4427

Published Oct 1, 2012

The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a crafted web page.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3146

Published Sep 5, 2012

librsvg before 2.34.1 uses the node name to identify the type of node, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference) and possibl…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3378

Published Aug 31, 2012

The register_application function in atk-adaptor/bridge.c in GNOME at-spi2-atk 2.5.2 does not seed the random number generator and generates predictable temporary file names, whic…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-1177

Published Aug 26, 2012

libgdata before 0.10.2 and 0.11.x before 0.11.1 does not validate SSL certificates, which allows remote attackers to obtain user names and passwords via a man-in-the-middle (MITM)…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2132

Published Aug 20, 2012

libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by co…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2370

Published Aug 13, 2012

Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in gdk-pixbuf before 2.26.1 allow remote attackers to cause a denial of service (application crash) vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3452

Published Aug 7, 2012

gnome-screensaver 3.4.x before 3.4.4 and 3.5.x before 3.5.4, when multiple screens are used, only locks the screen with the active focus, which allows physically proximate attacke…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-3355

Published Jul 17, 2012

(1) AlbumTab.py, (2) ArtistTab.py, (3) LinksTab.py, and (4) LyricsTab.py in the Context module in GNOME Rhythmbox 0.13.3 and earlier allows local users to execute arbitrary code v…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-2485

Published Jul 3, 2012

The gdk_pixbuf__gif_image_load function in gdk-pixbuf/io-gif.c in gdk-pixbuf before 2.23.5 does not properly handle certain return values, which allows remote attackers to cause a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0039

Published Jan 14, 2012

GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-de…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3364

Published Nov 4, 2011

Incomplete blacklist vulnerability in the svEscape function in settings/plugins/ifcfg-rh/shvar.c in the ifcfg-rh plug-in for GNOME NetworkManager 0.9.1, 0.9.0, 0.8.1, and possibly…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4170

Published Oct 23, 2011

Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3635

Published Oct 23, 2011

Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4833

Published Sep 6, 2011

Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan horse uxtheme.dll file in the…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4831

Published Sep 6, 2011

Untrusted search path vulnerability in gdk/win32/gdkinput-win32.c in GTK+ before 2.21.8 allows local users to gain privileges via a Trojan horse Wintab32.dll file in the current w…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2176

Published Sep 2, 2011

GNOME NetworkManager before 0.8.6 does not properly enforce the auth_admin element in PolicyKit, which allows local users to bypass intended wireless network sharing restrictions…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 226-250 of 359 CVEsPage 10 of 15