Skip to main content

Vendor archive

gnome CVEs

Beta · best-effort

359 CVEs tagged to vendor gnome32 Critical, 115 High, 175 Medium, 37 Low, 0 Unrated.

CVE-2007-3381

Published Aug 7, 2007

The GDM daemon in GNOME Display Manager (GDM) before 2.14.13, 2.16.x before 2.16.7, 2.18.x before 2.18.4, and 2.19.x before 2.19.5 does not properly handle NULL return values from…

CVSS 1.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-3257

Published Jun 19, 2007

Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, whi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0999

Published Mar 10, 2007

Format string vulnerability in Ekiga 2.0.3, and probably other versions, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-1266

Published Mar 6, 2007

Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0010

Published Jan 24, 2007

The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image fil…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-6698

Published Dec 22, 2006

The GConf daemon (gconfd) in GConf 2.14.0 creates temporary files under directories with names based on the username, even when GCONF_GLOBAL_LOCKS is not set, which allows local u…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-6105

Published Dec 15, 2006

Format string vulnerability in the host chooser window (gdmchooser) in GNOME Foundation Display Manager (gdm) allows local users to execute arbitrary code via format string specif…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3057

Published Jun 16, 2006

Unspecified vulnerability in NetworkManager daemon for DHCP (dhcdbd) allows remote attackers to cause a denial of service (crash) via certain invalid DHCP responses that trigger m…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2452

Published Jun 9, 2006

GNOME GDM 2.8, 2.12, 2.14, and 2.15, when the "face browser" feature is enabled, allows local users to access the "Configure Login Manager" functionality using their own password…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-2789

Published Jun 2, 2006

Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when "load images if sender in addressbook" is enabled, allows remote attackers to cause a denial of service (persistent crash) via…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-1057

Published Apr 25, 2006

Race condition in daemon/slave.c in gdm before 2.14.1 allows local users to gain privileges via a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-1335

Published Mar 21, 2006

gnome screensaver before 2.14, when running on an X server with AllowDeactivateGrabs and AllowClosedownGrabs enabled, allows attackers with physical access to cause the screensave…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-0819

Published Mar 13, 2006

Dwarf HTTP Server 1.3.2 allows remote attackers to obtain the source code of JSP files via (1) dot, (2) space, (3) slash, or (4) NULL characters in the filename extension of an HT…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0820

Published Mar 13, 2006

Cross-site scripting (XSS) vulnerability in Dwarf HTTP Server 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified error messages.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0040

Published Mar 10, 2006

GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0528

Published Feb 2, 2006

The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attache…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2975

Published Nov 18, 2005

io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large numb…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2976

Published Nov 18, 2005

Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large h…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3186

Published Nov 18, 2005

Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2958

Published Oct 25, 2005

Multiple format string vulnerabilities in the GNOME Data Access library for GNOME2 (libgda2) 1.2.1 and earlier allow attackers to execute arbitrary code.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0023

Published Oct 5, 2005

gnome-pty-helper in GNOME libzvt2 and libvte4 allows local users to spoof the logon hostname via a modified DISPLAY environment variable. NOTE: the severity of this issue has been…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-2549

Published Aug 12, 2005

Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) ful…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2550

Published Aug 12, 2005

Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2410

Published Aug 1, 2005

Format string vulnerability in the nm_info_handler function in Network Manager may allow remote attackers to execute arbitrary code via format string specifiers in a Wireless Acce…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 301-325 of 359 CVEsPage 13 of 15