Vulnerability index

Browse CVEs

154 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-2369 A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overr… Libsoup Patch available Fix from $2,3002026-03-19 HIGH 7.5 CVE-2025-4056 A flaw was found in GLib. A denial of service on Windows platforms may occur if an application attempts to spawn a program using long command lines. Glib 2.84.1+ Fix from $1,9502025-07-28 MEDIUM 5.5 CVE-2025-6196 A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB f… Libgepub No fix yet Fix from $1,6002025-06-17 HIGH 7.5 CVE-2025-6052 A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input ca… Glib after 2.84.3 Fix from $1,9502025-06-13 CRITICAL 9.8 CVE-2023-43091 A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is … Gnome Maps 43.7 / 44.4+ Fix from $2,3002024-11-17 HIGH 7.5 CVE-2024-52530 GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e.,… Libsoup 3.6.0+ Fix from $1,9502024-11-11 HIGH 7.5 CVE-2024-52532 GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients. Libsoup 3.6.1+ Fix from $1,9502024-11-11 MEDIUM 6.5 CVE-2024-52531 GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is… Libsoup 3.6.1+ Fix from $1,6002024-11-11 HIGH 7.8 CVE-2024-36474 An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) v… Libgsf Mitigation only Fix from $1,9502024-10-03 HIGH 7.8 CVE-2024-42415 An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Librar… Libgsf Mitigation only Fix from $1,9502024-10-03 MEDIUM 5.5 CVE-2020-36774 plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to a denial … Glade 3.38.1 / 3.40.0+ Fix from $1,6002024-02-19 HIGH 7.8 CVE-2022-48622 In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in ani_load_chunk i… Gdkpixbuf after 2.42.10 Fix from $1,9502024-01-26 HIGH 7.8 CVE-2023-32643 A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fix for CVE-2023-32665. This bu… Glib 2.75.1+ Fix from $1,9502023-09-14 HIGH 7.5 CVE-2023-29499 A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service. Glib 2.74.4+ Fix from $1,9502023-09-14 HIGH 7.5 CVE-2023-32636 A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation adde… Glib 2.74.4+ Fix from $1,9502023-09-14 MEDIUM 5.5 CVE-2023-32611 A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading… Glib 2.74.2+ Fix from $1,6002023-09-14 MEDIUM 5.5 CVE-2023-32665 A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processi… Glib 2.74.4+ Fix from $1,6002023-09-14 HIGH 7.8 CVE-2023-36250 CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating… Gnome Time Tracker No fix yet Fix from $1,9502023-09-14 HIGH 8.8 CVE-2019-25085 A vulnerability was found in GNOME gvdb. It has been classified as critical. This affects the function gvdb_table_write_contents_async of the file gv… Gvariant Database 2019-06-27+ Fix from $1,9502022-12-26 HIGH 7.5 CVE-2021-42522 There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrect use of … Anjuta Mitigation only Fix from $1,9502022-08-25 MEDIUM 5.5 CVE-2021-3982 Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privilege permissions, m… Gnome Shell Patch available Fix from $1,6002022-04-29 HIGH 7.5 CVE-2021-3567 A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that lev… Caribou 0.4.21+ Fix from $1,9502022-03-25 CRITICAL 9.8 CVE-2022-27811 GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename. Ocrfeeder 0.8.4+ Fix from $2,3002022-03-24 MEDIUM 6.1 CVE-2021-20315 A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window … Gnome Shell 3.32.2+ Fix from $1,6002022-02-18 MEDIUM 5.9 CVE-2021-39361 In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving… Evolution Rss after 0.3.96 Fix from $1,6002021-08-22 MEDIUM 5.5 CVE-2020-36427 GNOME gThumb before 3.10.1 allows an application crash via a malformed JPEG image. Gthumb 3.10.1+ Fix from $1,6002021-07-19 HIGH 7.8 CVE-2009-3721 Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF.… Evolution Patch available Fix from $1,9502021-05-26 HIGH 7.5 CVE-2016-20011 libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of f… Libgrss after 0.7.0 Fix from $1,9502021-05-25 HIGH 8.1 CVE-2021-33516 An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnera… Gupnp 1.0.7 / 1.2.5+ Fix from $1,9502021-05-24 MEDIUM 5.5 CVE-2020-14391 A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal cr… Control Center Mitigation only Fix from $1,6002021-02-08