Vulnerability index

Browse CVEs

154 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.4 CVE-2020-27837 A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock scre… Gnome Display Manager 3.38.2.1+ Fix from $1,6002020-12-28 HIGH 7.8 CVE-2020-35457 GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's positi… Glib 2.65.3+ Fix from $1,9502020-12-14 MEDIUM 6.8 CVE-2020-16125 gdm3 versions before 3.36.2 or 3.38.2 would start gnome-initial-setup if gdm3 can't contact the accountservice service via dbus in a timely manner; o… Gnome Display Manager 3.36.2 / 3.38.2+ Fix from $1,6002020-11-10 HIGH 7.5 CVE-2020-16118 In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PR… Balsa 2.6.0+ Fix from $1,9502020-07-29 HIGH 7.1 CVE-2020-12825 libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption. Libcroco after 0.6.13 Fix from $1,9502020-05-12 MEDIUM 6.5 CVE-2020-11879 An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other … Evolution 3.35.91+ Fix from $1,6002020-04-17 CRITICAL 9.8 CVE-2012-0828 Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial o… Gtk 2.8.6 / 1499-4+ Fix from $2,3002020-02-21 MEDIUM 6.8 CVE-2006-7246 NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used. Networkmanager after 0.9.9.98 Fix from $1,6002020-01-27 MEDIUM 5.5 CVE-2019-19308 In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing a TTF font file that lacks a … Gnome Font Viewer Patch available Fix from $1,6002019-11-27 HIGH 7.3 CVE-2011-3355 evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when… Evolution Data Server3 after 3.2.1 Fix from $1,9502019-11-25 HIGH 7.5 CVE-2019-13012 The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL,… Glib 2.59.1+ Fix from $1,9502019-06-28 HIGH 7.8 CVE-2019-12795 daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket witho… Gvfs 1.38.3 / 1.40.2+ Fix from $1,9502019-06-11 HIGH 8.1 CVE-2019-12448 An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c has race conditions because the admin backend doesn't implemen… Gvfs after 1.41.2 Fix from $1,9502019-05-29 CRITICAL 9.0 CVE-2019-11460 An issue was discovered in GNOME gnome-desktop 3.26, 3.28, and 3.30 prior to 3.30.2.2, and 3.32 prior to 3.32.1.1. A compromised thumbnailer may esca… Gnome Desktop 3.30.2.2 / 3.32.1.1+ Fix from $2,3002019-04-22 HIGH 7.8 CVE-2019-11461 An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox … Nautilus 3.30.6 / 3.32.1+ Fix from $1,9502019-04-22 HIGH 7.0 CVE-2019-3827 An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileg… Gvfs 1.39.4+ Fix from $1,9502019-03-25 MEDIUM 6.5 CVE-2019-9633 gio/gsocketclient.c in GNOME GLib 2.59.2 does not ensure that a parent GTask remains alive during the execution of a connection-attempting enumeratio… Glib Mitigation only Fix from $1,6002019-03-08 HIGH 7.8 CVE-2017-12447 GdkPixBuf (aka gdk-pixbuf), possibly 2.32.2, as used by GNOME Nautilus 3.14.3 on Ubuntu 16.04, allows attackers to cause a denial of service (stack c… Gdk Pixbuf No fix yet Fix from $1,9502019-03-07 HIGH 7.8 CVE-2018-19358 GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is… Gnome Keyring after 3.28.2 Fix from $1,9502018-11-18 MEDIUM 6.8 CVE-2008-7320 GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow dialog at an unattended worksta… Seahorse after 3.30 Fix from $1,6002018-11-18 HIGH 7.8 CVE-2018-14424 The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local at… Gnome Display Manager after 3.29.1 Fix from $1,9502018-08-14 MEDIUM 6.4 CVE-2017-12164 A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a vic… Gnome Display Manager Patch available Fix from $1,6002018-07-26 CRITICAL 9.8 CVE-2018-12422 addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer … Evolution after 3.29.2 Fix from $2,3002018-06-15 HIGH 7.5 CVE-2018-12016 libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via certain wind… Epiphany after 3.28.2.1 Fix from $1,9502018-06-07 HIGH 7.5 CVE-2018-11396 ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash… Epiphany after 3.28.2.1 Fix from $1,9502018-05-23 HIGH 7.8 CVE-2017-1000159 Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91. Evince 3.25.91+ Fix from $1,9502017-11-27 MEDIUM 5.5 CVE-2017-14108 libgedit.a in GNOME gedit through 3.22.1 allows remote attackers to cause a denial of service (CPU consumption) via a file that begins with many '\0'… Gedit after 3.22.1 Fix from $1,6002017-09-05 HIGH 7.5 CVE-2015-2675 The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows re… Librest Patch available Fix from $1,9502017-08-18 HIGH 7.5 CVE-2017-11590 There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of… Libgxps No fix yet Fix from $1,9502017-07-24 HIGH 7.8 CVE-2017-11464 A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because o… Librsvg Patch available Fix from $1,9502017-07-19