Skip to main content

Vendor archive

gnome CVEs

Beta · best-effort

359 CVEs tagged to vendor gnome32 Critical, 115 High, 175 Medium, 37 Low, 0 Unrated.

CVE-2017-11590

Published Jul 24, 2017

There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11464

Published Jul 19, 2017

A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because of incorrect protection against…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000044

Published Jul 17, 2017

gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when rendering

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-1000025

Published Jul 17, 2017

GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resultin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000024

Published Jul 17, 2017

Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11171

Published Jul 11, 2017

Bad reference counting in the context of accept_ice_connection() in gsm-xsmp-server.c in old versions of gnome-session up until version 2.29.92 allows a local attacker to establis…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8871

Published Jun 12, 2017

The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8834

Published Jun 12, 2017

The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (memory allocation error) via a crafted CSS file.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8288

Published Apr 27, 2017

gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander coul…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7961

Published Apr 19, 2017

The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable values of type long" undefined behavior issue, which might a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7960

Published Apr 19, 2017

The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6311

Published Mar 10, 2017

gdk-pixbuf-thumbnailer.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to prin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5885

Published Feb 28, 2017

Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-5884

Published Feb 28, 2017

gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a c…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6163

Published Feb 3, 2017

The rsvg_pattern_fix_fallback function in rsvg-paint_server.c in librsvg2 2.40.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted svg file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9888

Published Dec 8, 2016

An error within the "tar_directory_for_file()" function (gsf-infile-tar.c) in GNOME Structured File Library before 1.14.41 can be exploited to trigger a Null pointer dereference a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8875

Published Jun 1, 2016

Multiple integer overflows in the (1) pixops_composite_nearest, (2) pixops_composite_color_nearest, and (3) pixops_process functions in pixops/pixops.c in gdk-pixbuf before 2.33.1…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7558

Published May 20, 2016

librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via cyclic references in an SVG do…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 176-200 of 359 CVEsPage 8 of 15