Vulnerability index

Browse CVEs

154 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libsoup MEDIUM 5.0
CVE-2011-2524

Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (…

Fix: after 2.35.3
Fix from $1,600 2011-08-31
Gdm HIGH 7.2
CVE-2011-1709

GNOME Display Manager (gdm) before 2.32.2, when glib 2.28 is used, enables execution of a web browser with the uid of the gdm account, which allows l…

Patch available
Fix from $1,950 2011-06-14
Gdm MEDIUM 6.9
CVE-2011-0727

GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2)…

Patch available
Fix from $1,600 2011-03-31
Pango HIGH 7.6
CVE-2011-0020EPSS 19%

Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when t…

Fix: after 1.28.3
Fix from $1,950 2011-01-24
Gnome Shell MEDIUM 6.9
CVE-2010-4000

gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Troja…

Mitigation only
Fix from $1,600 2010-11-06
Tomboy MEDIUM 6.9
CVE-2010-4005

The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows…

Fix: after 1.5.2
Fix from $1,600 2010-11-06
Epiphany MEDIUM 5.8
CVE-2010-3312

Epiphany 2.28 and 2.29, when WebKit and LibSoup are used, unconditionally displays a closed-lock icon for any URL beginning with the https: substring…

Mitigation only
Fix from $1,600 2010-10-14
Power Manager HIGH 7.2
CVE-2006-7240

gnome-power-manager 2.14.0 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or …

Mitigation only
Fix from $1,950 2010-09-07
Power Manager HIGH 7.2
CVE-2009-4997

gnome-power-manager 2.27.92 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or…

Mitigation only
Fix from $1,950 2010-09-07
Gtk MEDIUM 6.2
CVE-2010-0732

gdk/gdkwindow.c in GTK+ before 2.18.5, as used in gnome-screensaver before 2.28.1, performs implicit paints on windows of type GDK_WINDOW_FOREIGN, wh…

Fix: 2.18.5 / 2.28.1+
Fix from $1,600 2010-03-19
Screensaver MEDIUM 5.6
CVE-2010-0285

gnome-screensaver 2.14.3, 2.22.2, 2.27.x, 2.28.0, and 2.28.3, when the X configuration enables the extend screen option, allows physically proximate …

Mitigation only
Fix from $1,600 2010-02-24
Screensaver HIGH 7.2
CVE-2009-4641

gnome-screensaver 2.28.0 does not resume adherence to its activation settings after an inhibiting application becomes unavailable on the session bus,…

Patch available
Fix from $1,950 2010-02-11
Screensaver HIGH 7.2
CVE-2009-4642

gnome-screensaver 2.26.1 relies on the gnome-session D-Bus interface to determine session idle time, even when an Xfce desktop such as Xubuntu or Myt…

Mitigation only
Fix from $1,950 2010-02-11
Screensaver HIGH 7.2
CVE-2010-0414

gnome-screensaver before 2.28.2 allows physically proximate attackers to bypass screen locking and access an unattended workstation by moving the mou…

Fix: after 2.28.1
Fix from $1,950 2010-02-11
Gmime HIGH 7.5
CVE-2010-0409

Buffer overflow in the GMIME_UUENCODE_LEN macro in gmime/gmime-encodings.h in GMime before 2.4.15 allows context-dependent attackers to cause a denia…

Patch available
Fix from $1,950 2010-02-08
Networkmanager MEDIUM 6.8
CVE-2009-4144

NetworkManager (NM) 0.7.2 does not ensure that the configured Certification Authority (CA) certificate file for a (1) WPA Enterprise or (2) 802.1x ne…

Mitigation only
Fix from $1,600 2009-12-23
Gpdf HIGH 9.3
CVE-2009-4035

The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, d…

Mitigation only
Fix from $1,950 2009-12-21
Glib HIGH 7.8
CVE-2009-3289

The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted lo…

No fix yet
Fix from $1,950 2009-09-22
Gdm MEDIUM 6.8
CVE-2009-2697

The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which m…

Fix: after 2.16
Fix from $1,600 2009-09-04
Evolution Data Server MEDIUM 5.8
CVE-2009-0582

The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-dat…

Fix: after 2.24.5
Fix from $1,600 2009-03-14
Epiphany MEDIUM 6.9
CVE-2008-5985

Untrusted search path vulnerability in the Python interface in Epiphany 2.22.3, and possibly other versions, allows local users to execute arbitrary …

Mitigation only
Fix from $1,600 2009-01-28
Eog MEDIUM 6.9
CVE-2008-5987

Untrusted search path vulnerability in the Python interface in Eye of GNOME (eog) 2.22.3, and possibly other versions, allows local users to execute …

Mitigation only
Fix from $1,600 2009-01-28
Nautilus Python MEDIUM 6.9
CVE-2009-0317

Untrusted search path vulnerability in the Python language bindings for Nautilus (nautilus-python) allows local users to execute arbitrary code via a…

Mitigation only
Fix from $1,600 2009-01-28
Gnumeric MEDIUM 6.9
CVE-2009-0318

Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan h…

Mitigation only
Fix from $1,600 2009-01-28
Vinagre MEDIUM 6.8
CVE-2008-5660EPSS 9%

Format string vulnerability in the vinagre_utils_show_error function (src/vinagre-utils.c) in Vinagre 0.5.x before 0.5.2 and 2.x before 2.24.2 might …

No fix yet
Fix from $1,600 2008-12-17
Yelp HIGH 10.0
CVE-2008-3533EPSS 19%

Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to e…

Fix: 2.24+
Fix from $1,950 2008-08-18
Evolution HIGH 9.3
CVE-2008-1109EPSS 6%

Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an …

Mitigation only
Fix from $1,950 2008-06-04
Evolution HIGH 7.6
CVE-2008-1108EPSS 6%

Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezon…

Mitigation only
Fix from $1,950 2008-06-04
Evolution MEDIUM 6.8
CVE-2008-0072EPSS 6%

Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to ex…

Fix: after 2.12.3
Fix from $1,600 2008-03-06
Gnumeric HIGH 9.3
CVE-2008-0668

The excel_read_HLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute…

Fix: after 1.7.91
Fix from $1,950 2008-02-11