Skip to main content

Vendor archive

gnome CVEs

Beta · best-effort

359 CVEs tagged to vendor gnome32 Critical, 115 High, 175 Medium, 37 Low, 0 Unrated.

CVE-2018-15120

Published Aug 24, 2018

libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecifi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14424

Published Aug 14, 2018

The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12164

Published Jul 26, 2018

A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10727

Published Jul 20, 2018

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wis…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-12422

Published Jun 15, 2018

addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-12016

Published Jun 7, 2018

libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via certain window.open and document.write cal…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11713

Published Jun 4, 2018

WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, une…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11396

Published May 23, 2018

ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that tri…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17689

Published May 16, 2018

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2017-2885

Published Apr 24, 2018

An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow resulting in remote code exe…

CVSS 9.8 · Critical

CVE-2018-1000041

Published Feb 9, 2018

GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can result in the victim's Window…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5345

Published Jan 12, 2018

A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab f…

CVSS 7.8 · High

CVE-2017-1000159

Published Nov 27, 2017

Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14604

Published Sep 20, 2017

GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .desktop file's Name field ends i…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2870

Published Sep 5, 2017

An exploitable integer overflow vulnerability exists in the tiff_image_parse functionality of Gdk-Pixbuf 2.36.6 when compiled with Clang. A specially crafted tiff file can cause a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2862

Published Sep 5, 2017

An exploitable heap overflow vulnerability exists in the gdk_pixbuf__jpeg_image_load_increment functionality of Gdk-Pixbuf 2.36.6. A specially crafted jpeg file can cause a heap o…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14108

Published Sep 5, 2017

libgedit.a in GNOME gedit through 3.22.1 allows remote attackers to cause a denial of service (CPU consumption) via a file that begins with many '\0' characters.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000083

Published Sep 5, 2017

backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR arc…

CVSS 7.8 · High

CVE-2015-2675

Published Aug 18, 2017

The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a deni…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 359 CVEsPage 7 of 15