Vulnerability index

Browse CVEs

154 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gnome Display Manager MEDIUM 6.4
CVE-2020-27837

A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock scre…

Fix: 3.38.2.1+
Fix from $1,600 2020-12-28
Glib HIGH 7.8
CVE-2020-35457

GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's positi…

Fix: 2.65.3+
Fix from $1,950 2020-12-14
Gnome Display Manager MEDIUM 6.8
CVE-2020-16125

gdm3 versions before 3.36.2 or 3.38.2 would start gnome-initial-setup if gdm3 can't contact the accountservice service via dbus in a timely manner; o…

Fix: 3.36.2 / 3.38.2+
Fix from $1,600 2020-11-10
Balsa HIGH 7.5
CVE-2020-16118

In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PR…

Fix: 2.6.0+
Fix from $1,950 2020-07-29
Libcroco HIGH 7.1
CVE-2020-12825

libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.

Fix: after 0.6.13
Fix from $1,950 2020-05-12
Evolution MEDIUM 6.5
CVE-2020-11879

An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other …

Fix: 3.35.91+
Fix from $1,600 2020-04-17
Gtk CRITICAL 9.8
CVE-2012-0828

Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial o…

Fix: 2.8.6 / 1499-4+
Fix from $2,300 2020-02-21
Networkmanager MEDIUM 6.8
CVE-2006-7246

NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.

Fix: after 0.9.9.98
Fix from $1,600 2020-01-27
Gnome Font Viewer MEDIUM 5.5
CVE-2019-19308

In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing a TTF font file that lacks a …

Patch available
Fix from $1,600 2019-11-27
Evolution Data Server3 HIGH 7.3
CVE-2011-3355

evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when…

Fix: after 3.2.1
Fix from $1,950 2019-11-25
Glib HIGH 7.5
CVE-2019-13012

The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL,…

Fix: 2.59.1+
Fix from $1,950 2019-06-28
Gvfs HIGH 7.8
CVE-2019-12795

daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket witho…

Fix: 1.38.3 / 1.40.2+
Fix from $1,950 2019-06-11
Gvfs HIGH 8.1
CVE-2019-12448

An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c has race conditions because the admin backend doesn't implemen…

Fix: after 1.41.2
Fix from $1,950 2019-05-29
Gnome Desktop CRITICAL 9.0
CVE-2019-11460

An issue was discovered in GNOME gnome-desktop 3.26, 3.28, and 3.30 prior to 3.30.2.2, and 3.32 prior to 3.32.1.1. A compromised thumbnailer may esca…

Fix: 3.30.2.2 / 3.32.1.1+
Fix from $2,300 2019-04-22
Nautilus HIGH 7.8
CVE-2019-11461

An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox …

Fix: 3.30.6 / 3.32.1+
Fix from $1,950 2019-04-22
Gvfs HIGH 7.0
CVE-2019-3827

An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileg…

Fix: 1.39.4+
Fix from $1,950 2019-03-25
Glib MEDIUM 6.5
CVE-2019-9633

gio/gsocketclient.c in GNOME GLib 2.59.2 does not ensure that a parent GTask remains alive during the execution of a connection-attempting enumeratio…

Mitigation only
Fix from $1,600 2019-03-08
Gdk Pixbuf HIGH 7.8
CVE-2017-12447

GdkPixBuf (aka gdk-pixbuf), possibly 2.32.2, as used by GNOME Nautilus 3.14.3 on Ubuntu 16.04, allows attackers to cause a denial of service (stack c…

No fix yet
Fix from $1,950 2019-03-07
Gnome Keyring HIGH 7.8
CVE-2018-19358

GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is…

Fix: after 3.28.2
Fix from $1,950 2018-11-18
Seahorse MEDIUM 6.8
CVE-2008-7320

GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow dialog at an unattended worksta…

Fix: after 3.30
Fix from $1,600 2018-11-18
Gnome Display Manager HIGH 7.8
CVE-2018-14424

The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local at…

Fix: after 3.29.1
Fix from $1,950 2018-08-14
Gnome Display Manager MEDIUM 6.4
CVE-2017-12164

A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a vic…

Patch available
Fix from $1,600 2018-07-26
Evolution CRITICAL 9.8
CVE-2018-12422

addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer …

Fix: after 3.29.2
Fix from $2,300 2018-06-15
Epiphany HIGH 7.5
CVE-2018-12016

libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via certain wind…

Fix: after 3.28.2.1
Fix from $1,950 2018-06-07
Epiphany HIGH 7.5
CVE-2018-11396

ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash…

Fix: after 3.28.2.1
Fix from $1,950 2018-05-23
Evince HIGH 7.8
CVE-2017-1000159

Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.

Fix: 3.25.91+
Fix from $1,950 2017-11-27
Gedit MEDIUM 5.5
CVE-2017-14108

libgedit.a in GNOME gedit through 3.22.1 allows remote attackers to cause a denial of service (CPU consumption) via a file that begins with many '\0'…

Fix: after 3.22.1
Fix from $1,600 2017-09-05
Librest HIGH 7.5
CVE-2015-2675

The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows re…

Patch available
Fix from $1,950 2017-08-18
Libgxps HIGH 7.5
CVE-2017-11590

There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of…

No fix yet
Fix from $1,950 2017-07-24
Librsvg HIGH 7.8
CVE-2017-11464

A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because o…

Patch available
Fix from $1,950 2017-07-19