Vulnerability index

Browse CVEs

154 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Balsa MEDIUM 6.8
CVE-2007-5007

Stack-based buffer overflow in the ir_fetch_seq function in balsa before 2.3.20 might allow remote IMAP servers to execute arbitrary code via a long …

Patch available
Fix from $1,600 2007-12-12
Evolution MEDIUM 6.8
CVE-2007-3257

Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negativ…

Mitigation only
Fix from $1,600 2007-06-19
Ekiga HIGH 9.3
CVE-2007-0999

Format string vulnerability in Ekiga 2.0.3, and probably other versions, allows remote attackers to execute arbitrary code via unspecified vectors, a…

Fix: after 2.0.3
Fix from $1,950 2007-03-10
Evolution MEDIUM 5.0
CVE-2007-1266EPSS 5%

Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing…

Fix: after 2.8.1
Fix from $1,600 2007-03-06
Dhcdbd MEDIUM 5.0
CVE-2006-3057

Unspecified vulnerability in NetworkManager daemon for DHCP (dhcdbd) allows remote attackers to cause a denial of service (crash) via certain invalid…

Mitigation only
Fix from $1,600 2006-06-16
Dwarf Http Server HIGH 7.8
CVE-2006-0819

Dwarf HTTP Server 1.3.2 allows remote attackers to obtain the source code of JSP files via (1) dot, (2) space, (3) slash, or (4) NULL characters in t…

Patch available
Fix from $1,950 2006-03-13
Evolution MEDIUM 5.0
CVE-2006-0040

GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large …

Mitigation only
Fix from $1,600 2006-03-10
Evolution MEDIUM 5.0
CVE-2006-0528EPSS 11%

The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persisten…

No fix yet
Fix from $1,600 2006-02-02
Gdkpixbuf HIGH 7.8
CVE-2005-2975

io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a craft…

Fix: 2.8.7+
Fix from $1,950 2005-11-18
Gdkpixbuf HIGH 7.5
CVE-2005-2976

Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary cod…

Fix: 2.8.7+
Fix from $1,950 2005-11-18
Gdkpixbuf HIGH 7.5
CVE-2005-3186

Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a n…

Patch available
Fix from $1,950 2005-11-18
Libgda2 HIGH 7.5
CVE-2005-2958

Multiple format string vulnerabilities in the GNOME Data Access library for GNOME2 (libgda2) 1.2.1 and earlier allow attackers to execute arbitrary c…

Fix: after 1.2.1
Fix from $1,950 2005-10-25
Evolution HIGH 7.5
CVE-2005-2549

Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly exec…

Mitigation only
Fix from $1,950 2005-08-12
Evolution HIGH 7.5
CVE-2005-2550

Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitr…

Mitigation only
Fix from $1,950 2005-08-12
Networkmanager HIGH 7.5
CVE-2005-2410

Format string vulnerability in the nm_info_handler function in Network Manager may allow remote attackers to execute arbitrary code via format string…

Fix: 0.4.1+
Fix from $1,950 2005-08-01
Gtk HIGH 7.5
CVE-2005-0891

Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.

Fix: 2.2.4+
Fix from $1,950 2005-05-02
Epiphany MEDIUM 5.0
CVE-2005-0238

The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are de…

Fix: after 7.54
Fix from $1,600 2005-05-02
Gtk MEDIUM 5.0
CVE-2005-0372

Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequenc…

Fix: 2.0.18+
Fix from $1,600 2005-05-02
Gdkpixbuf HIGH 7.5
CVE-2004-0782EPSS 9%

Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows …

Patch available
Fix from $1,950 2004-10-20
Gdkpixbuf HIGH 7.5
CVE-2004-0783EPSS 9%

Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, m…

Patch available
Fix from $1,950 2004-10-20
Gdkpixbuf MEDIUM 5.0
CVE-2004-0753EPSS 6%

The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop)…

Fix: 2.2.4+
Fix from $1,600 2004-10-20
Gdkpixbuf MEDIUM 5.0
CVE-2004-0788EPSS 6%

Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of servi…

Fix: 2.2.4+
Fix from $1,600 2004-10-20
Gtkhtml MEDIUM 5.0
CVE-2003-0541

gtkhtml before 1.1.10, as used in Evolution, allows remote attackers to cause a denial of service (crash) via a malformed message that causes a null …

Fix: after 1.1.10
Fix from $1,600 2003-09-17
Batalla Naval HIGH 10.0
CVE-2003-0407EPSS 16%

Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.

No fix yet
Fix from $1,950 2003-06-30
Gtkhtml MEDIUM 5.0
CVE-2003-0133

GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.

Patch available
Fix from $1,600 2003-05-05
Gnome Lokkit HIGH 7.5
CVE-2003-0080

The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass inte…

Patch available
Fix from $1,950 2003-03-31
Libgtop Daemon HIGH 7.5
CVE-2001-0928EPSS 6%

Buffer overflow in the permitted function of GNOME gtop daemon (libgtop_daemon) in libgtop 1.0.13 and earlier may allow remote attackers to execute a…

Patch available
Fix from $1,950 2001-11-28
Libgtop Daemon HIGH 7.5
CVE-2001-0927

Format string vulnerability in the permitted function of GNOME libgtop_daemon in libgtop 1.0.12 and earlier allows remote attackers to execute arbitr…

Patch available
Fix from $1,950 2001-11-27
Gtk HIGH 7.2
CVE-2001-0084

GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privil…

Patch available
Fix from $1,950 2001-02-12
Gnorpm HIGH 7.2
CVE-2000-0948

GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.

Fix: after 0.94
Fix from $1,950 2000-12-19