Skip to main content

Vendor archive

gnome CVEs

Beta · best-effort

359 CVEs tagged to vendor gnome32 Critical, 115 High, 175 Medium, 37 Low, 0 Unrated.

CVE-2015-7557

Published May 20, 2016

The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0272

Published Nov 17, 2015

GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message, a differe…

CVSS 5.0 · Medium

CVE-2015-7673

Published Oct 26, 2015

io-tga.c in gdk-pixbuf before 2.32.0 uses heap memory after its allocation failed, which allows remote attackers to cause a denial of service (heap-based buffer overflow and appli…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2785

Published Mar 29, 2015

The GIF encoder in Byzanz allows remote attackers to cause a denial of service (out-of-bounds heap write and crash) or possibly execute arbitrary code via a crafted Byzanz debug d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8154

Published Jan 27, 2015

The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-dependent attackers to cause a deni…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0552

Published Jan 15, 2015

Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder.c in gcab 0.4 allows remote attackers to write to arbitrary files via crafted path in…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7273

Published Apr 29, 2014

GNOME Display Manager (gdm) 3.4.1 and earlier, when disable-user-list is set to true, allows local users to cause a denial of service (unable to login) by pressing the cancel butt…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-7221

Published Apr 29, 2014

The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Enter a Command" dialog, which allows physically proximate att…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7220

Published Apr 29, 2014

js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6836

Published Dec 19, 2013

Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of serv…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1881

Published Oct 10, 2013

GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, r…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4169

Published Sep 10, 2013

GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1050

Published Mar 8, 2013

The default configuration in gnome-screensaver 3.5.4 through 3.6.0 sets the AutostartCondition line to fallback mode in the .desktop file, which prevents the program from starting…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 201-225 of 359 CVEsPage 9 of 15