Vulnerability index

Browse CVEs

42 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Libgepub MEDIUM 5.5
CVE-2025-6196

A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB f…

No fix yet
Fix from $1,600 2025-06-17
Libgsf HIGH 7.8
CVE-2024-36474

An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) v…

Mitigation only
Fix from $1,950 2024-10-03
Libgsf HIGH 7.8
CVE-2024-42415

An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Librar…

Mitigation only
Fix from $1,950 2024-10-03
Gnome Time Tracker HIGH 7.8
CVE-2023-36250

CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating…

No fix yet
Fix from $1,950 2023-09-14
Anjuta HIGH 7.5
CVE-2021-42522

There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrect use of …

Mitigation only
Fix from $1,950 2022-08-25
Control Center MEDIUM 5.5
CVE-2020-14391

A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal cr…

Mitigation only
Fix from $1,600 2021-02-08
Glib MEDIUM 6.5
CVE-2019-9633

gio/gsocketclient.c in GNOME GLib 2.59.2 does not ensure that a parent GTask remains alive during the execution of a connection-attempting enumeratio…

Mitigation only
Fix from $1,600 2019-03-08
Gdk Pixbuf HIGH 7.8
CVE-2017-12447

GdkPixBuf (aka gdk-pixbuf), possibly 2.32.2, as used by GNOME Nautilus 3.14.3 on Ubuntu 16.04, allows attackers to cause a denial of service (stack c…

No fix yet
Fix from $1,950 2019-03-07
Libgxps HIGH 7.5
CVE-2017-11590

There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of…

No fix yet
Fix from $1,950 2017-07-24
Epiphany HIGH 7.5
CVE-2017-1000025

GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password…

Mitigation only
Fix from $1,950 2017-07-17
Libcroco MEDIUM 6.5
CVE-2017-8834

The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (memory allocation error) v…

No fix yet
Fix from $1,600 2017-06-12
Libcroco MEDIUM 6.5
CVE-2017-8871EPSS 13%

The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and …

No fix yet
Fix from $1,600 2017-06-12
Byzanz HIGH 7.5
CVE-2015-2785

The GIF encoder in Byzanz allows remote attackers to cause a denial of service (out-of-bounds heap write and crash) or possibly execute arbitrary cod…

Mitigation only
Fix from $1,950 2015-03-29
Gcab MEDIUM 6.4
CVE-2015-0552

Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder.c in gcab 0.4 allows remote attackers to write to arbitr…

No fix yet
Fix from $1,600 2015-01-15
Gnome Screensaver HIGH 7.2
CVE-2013-1050

The default configuration in gnome-screensaver 3.5.4 through 3.6.0 sets the AutostartCondition line to fallback mode in the .desktop file, which prev…

Mitigation only
Fix from $1,950 2013-03-08
Evince MEDIUM 6.8
CVE-2011-5244

Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME ev…

Mitigation only
Fix from $1,600 2012-11-19
Evince MEDIUM 6.8
CVE-2011-0433

Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow…

Mitigation only
Fix from $1,600 2012-11-19
Gnome Shell MEDIUM 6.8
CVE-2012-4427

The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.or…

No fix yet
Fix from $1,600 2012-10-01
Libsoup MEDIUM 5.0
CVE-2012-2132

libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers …

Mitigation only
Fix from $1,600 2012-08-20
Gnome Shell MEDIUM 6.9
CVE-2010-4000

gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Troja…

Mitigation only
Fix from $1,600 2010-11-06
Epiphany MEDIUM 5.8
CVE-2010-3312

Epiphany 2.28 and 2.29, when WebKit and LibSoup are used, unconditionally displays a closed-lock icon for any URL beginning with the https: substring…

Mitigation only
Fix from $1,600 2010-10-14
Power Manager HIGH 7.2
CVE-2006-7240

gnome-power-manager 2.14.0 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or …

Mitigation only
Fix from $1,950 2010-09-07
Power Manager HIGH 7.2
CVE-2009-4997

gnome-power-manager 2.27.92 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or…

Mitigation only
Fix from $1,950 2010-09-07
Screensaver MEDIUM 5.6
CVE-2010-0285

gnome-screensaver 2.14.3, 2.22.2, 2.27.x, 2.28.0, and 2.28.3, when the X configuration enables the extend screen option, allows physically proximate …

Mitigation only
Fix from $1,600 2010-02-24
Screensaver HIGH 7.2
CVE-2009-4642

gnome-screensaver 2.26.1 relies on the gnome-session D-Bus interface to determine session idle time, even when an Xfce desktop such as Xubuntu or Myt…

Mitigation only
Fix from $1,950 2010-02-11
Networkmanager MEDIUM 6.8
CVE-2009-4144

NetworkManager (NM) 0.7.2 does not ensure that the configured Certification Authority (CA) certificate file for a (1) WPA Enterprise or (2) 802.1x ne…

Mitigation only
Fix from $1,600 2009-12-23
Gpdf HIGH 9.3
CVE-2009-4035

The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, d…

Mitigation only
Fix from $1,950 2009-12-21
Glib HIGH 7.8
CVE-2009-3289

The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted lo…

No fix yet
Fix from $1,950 2009-09-22
Epiphany MEDIUM 6.9
CVE-2008-5985

Untrusted search path vulnerability in the Python interface in Epiphany 2.22.3, and possibly other versions, allows local users to execute arbitrary …

Mitigation only
Fix from $1,600 2009-01-28
Eog MEDIUM 6.9
CVE-2008-5987

Untrusted search path vulnerability in the Python interface in Eye of GNOME (eog) 2.22.3, and possibly other versions, allows local users to execute …

Mitigation only
Fix from $1,600 2009-01-28