Vulnerability index

Browse CVEs

154 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gtk Vnc CRITICAL 9.8
CVE-2017-1000044

gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when rendering

Patch available
Fix from $2,300 2017-07-17
Shotwell HIGH 7.5
CVE-2017-1000024

Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potent…

Fix: after 0.25.3
Fix from $1,950 2017-07-17
Epiphany HIGH 7.5
CVE-2017-1000025

GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password…

Mitigation only
Fix from $1,950 2017-07-17
Gnome Session MEDIUM 5.5
CVE-2017-11171

Bad reference counting in the context of accept_ice_connection() in gsm-xsmp-server.c in old versions of gnome-session up until version 2.29.92 allow…

Fix: after 2.29.92
Fix from $1,600 2017-07-11
Libcroco MEDIUM 6.5
CVE-2017-8834

The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (memory allocation error) v…

No fix yet
Fix from $1,600 2017-06-12
Libcroco MEDIUM 6.5
CVE-2017-8871EPSS 13%

The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and …

No fix yet
Fix from $1,600 2017-06-12
Gnome Shell HIGH 8.1
CVE-2017-8288

gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With thes…

Patch available
Fix from $1,950 2017-04-27
Libcroco HIGH 7.8
CVE-2017-7961

The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable values of type long" undefined…

Patch available
Fix from $1,950 2017-04-19
Libcroco MEDIUM 5.5
CVE-2017-7960

The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffe…

Patch available
Fix from $1,600 2017-04-19
Librsvg MEDIUM 5.5
CVE-2016-6163

The rsvg_pattern_fix_fallback function in rsvg-paint_server.c in librsvg2 2.40.2 allows remote attackers to cause a denial of service (out-of-bounds …

Patch available
Fix from $1,600 2017-02-03
Libgsf MEDIUM 5.5
CVE-2016-9888

An error within the "tar_directory_for_file()" function (gsf-infile-tar.c) in GNOME Structured File Library before 1.14.41 can be exploited to trigge…

Fix: after 1.14.40
Fix from $1,600 2016-12-08
Librsvg HIGH 7.5
CVE-2015-7557

The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (ou…

Fix: after 2.40.6
Fix from $1,950 2016-05-20
Byzanz HIGH 7.5
CVE-2015-2785

The GIF encoder in Byzanz allows remote attackers to cause a denial of service (out-of-bounds heap write and crash) or possibly execute arbitrary cod…

Mitigation only
Fix from $1,950 2015-03-29
Vala HIGH 7.5
CVE-2014-8154

The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-depen…

Patch available
Fix from $1,950 2015-01-27
Gcab MEDIUM 6.4
CVE-2015-0552

Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder.c in gcab 0.4 allows remote attackers to write to arbitr…

No fix yet
Fix from $1,600 2015-01-15
Gnome Display Manager MEDIUM 6.9
CVE-2013-4169

GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/.

Fix: after 2.21
Fix from $1,600 2013-09-10
Gnome Screensaver HIGH 7.2
CVE-2013-1050

The default configuration in gnome-screensaver 3.5.4 through 3.6.0 sets the AutostartCondition line to fallback mode in the .desktop file, which prev…

Mitigation only
Fix from $1,950 2013-03-08
Evince MEDIUM 6.8
CVE-2011-5244

Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME ev…

Mitigation only
Fix from $1,600 2012-11-19
Evince MEDIUM 6.8
CVE-2011-0433

Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow…

Mitigation only
Fix from $1,600 2012-11-19
Libsocialweb MEDIUM 5.8
CVE-2012-4511

services/flickr/flickr.c in libsocialweb before 0.25.21 automatically connects to Flickr when no Flickr account is set, which might allow remote atta…

Fix: after 0.25.20
Fix from $1,600 2012-10-22
Libsocialweb MEDIUM 5.8
CVE-2011-4129

(1) services/twitter/twitter-contact-view.c and (2) services/twitter/twitter-item-view.c in libsocialweb before 0.25.20 automatically connect to Twit…

Fix: after 0.25.19
Fix from $1,600 2012-10-22
Gnome Shell MEDIUM 6.8
CVE-2012-4427

The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.or…

No fix yet
Fix from $1,600 2012-10-01
Librsvg MEDIUM 6.8
CVE-2011-3146

librsvg before 2.34.1 uses the node name to identify the type of node, which allows context-dependent attackers to cause a denial of service (NULL po…

Fix: after 2.34.0
Fix from $1,600 2012-09-05
Libgdata MEDIUM 5.1
CVE-2012-1177

libgdata before 0.10.2 and 0.11.x before 0.11.1 does not validate SSL certificates, which allows remote attackers to obtain user names and passwords …

Fix: after 0.11.0
Fix from $1,600 2012-08-26
Libsoup MEDIUM 5.0
CVE-2012-2132

libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers …

Mitigation only
Fix from $1,600 2012-08-20
Gdk Pixbuf MEDIUM 5.0
CVE-2012-2370

Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in gdk-pixbuf before 2.26.1 allow remote attackers to cause a denial of …

Fix: after 2.26.0
Fix from $1,600 2012-08-13
Glib HIGH 7.5
CVE-2012-0039

GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predic…

Fix: after 2.31.8
Fix from $1,950 2012-01-14
Ifcfg Rh Plug In MEDIUM 6.9
CVE-2011-3364

Incomplete blacklist vulnerability in the svEscape function in settings/plugins/ifcfg-rh/shvar.c in the ifcfg-rh plug-in for GNOME NetworkManager 0.9…

Patch available
Fix from $1,600 2011-11-04
Gtk HIGH 9.3
CVE-2010-4833

Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan…

Fix: 2.24.0+
Fix from $1,950 2011-09-06
Gtk MEDIUM 6.9
CVE-2010-4831

Untrusted search path vulnerability in gdk/win32/gdkinput-win32.c in GTK+ before 2.21.8 allows local users to gain privileges via a Trojan horse Wint…

Fix: 2.21.8+
Fix from $1,600 2011-09-06