Vulnerability index

Browse CVEs

154 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libsoup CRITICAL 9.1
CVE-2026-2369

A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overr…

Patch available
Fix from $2,300 2026-03-19
Glib HIGH 7.5
CVE-2025-4056

A flaw was found in GLib. A denial of service on Windows platforms may occur if an application attempts to spawn a program using long command lines.

Fix: 2.84.1+
Fix from $1,950 2025-07-28
Libgepub MEDIUM 5.5
CVE-2025-6196

A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB f…

No fix yet
Fix from $1,600 2025-06-17
Glib HIGH 7.5
CVE-2025-6052

A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input ca…

Fix: after 2.84.3
Fix from $1,950 2025-06-13
Gnome Maps CRITICAL 9.8
CVE-2023-43091

A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is …

Fix: 43.7 / 44.4+
Fix from $2,300 2024-11-17
Libsoup HIGH 7.5
CVE-2024-52530

GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e.,…

Fix: 3.6.0+
Fix from $1,950 2024-11-11
Libsoup HIGH 7.5
CVE-2024-52532

GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.

Fix: 3.6.1+
Fix from $1,950 2024-11-11
Libsoup MEDIUM 6.5
CVE-2024-52531

GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is…

Fix: 3.6.1+
Fix from $1,600 2024-11-11
Libgsf HIGH 7.8
CVE-2024-36474

An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) v…

Mitigation only
Fix from $1,950 2024-10-03
Libgsf HIGH 7.8
CVE-2024-42415

An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Librar…

Mitigation only
Fix from $1,950 2024-10-03
Glade MEDIUM 5.5
CVE-2020-36774

plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to a denial …

Fix: 3.38.1 / 3.40.0+
Fix from $1,600 2024-02-19
Gdkpixbuf HIGH 7.8
CVE-2022-48622

In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in ani_load_chunk i…

Fix: after 2.42.10
Fix from $1,950 2024-01-26
Glib HIGH 7.8
CVE-2023-32643

A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fix for CVE-2023-32665. This bu…

Fix: 2.75.1+
Fix from $1,950 2023-09-14
Glib HIGH 7.5
CVE-2023-29499

A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.

Fix: 2.74.4+
Fix from $1,950 2023-09-14
Glib HIGH 7.5
CVE-2023-32636

A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation adde…

Fix: 2.74.4+
Fix from $1,950 2023-09-14
Glib MEDIUM 5.5
CVE-2023-32611

A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading…

Fix: 2.74.2+
Fix from $1,600 2023-09-14
Glib MEDIUM 5.5
CVE-2023-32665

A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processi…

Fix: 2.74.4+
Fix from $1,600 2023-09-14
Gnome Time Tracker HIGH 7.8
CVE-2023-36250

CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating…

No fix yet
Fix from $1,950 2023-09-14
Gvariant Database HIGH 8.8
CVE-2019-25085

A vulnerability was found in GNOME gvdb. It has been classified as critical. This affects the function gvdb_table_write_contents_async of the file gv…

Fix: 2019-06-27+
Fix from $1,950 2022-12-26
Anjuta HIGH 7.5
CVE-2021-42522

There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrect use of …

Mitigation only
Fix from $1,950 2022-08-25
Gnome Shell MEDIUM 5.5
CVE-2021-3982

Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privilege permissions, m…

Patch available
Fix from $1,600 2022-04-29
Caribou HIGH 7.5
CVE-2021-3567

A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that lev…

Fix: 0.4.21+
Fix from $1,950 2022-03-25
Ocrfeeder CRITICAL 9.8
CVE-2022-27811

GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.

Fix: 0.8.4+
Fix from $2,300 2022-03-24
Gnome Shell MEDIUM 6.1
CVE-2021-20315

A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window …

Fix: 3.32.2+
Fix from $1,600 2022-02-18
Evolution Rss MEDIUM 5.9
CVE-2021-39361

In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving…

Fix: after 0.3.96
Fix from $1,600 2021-08-22
Gthumb MEDIUM 5.5
CVE-2020-36427

GNOME gThumb before 3.10.1 allows an application crash via a malformed JPEG image.

Fix: 3.10.1+
Fix from $1,600 2021-07-19
Evolution HIGH 7.8
CVE-2009-3721

Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF.…

Patch available
Fix from $1,950 2021-05-26
Libgrss HIGH 7.5
CVE-2016-20011

libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of f…

Fix: after 0.7.0
Fix from $1,950 2021-05-25
Gupnp HIGH 8.1
CVE-2021-33516

An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnera…

Fix: 1.0.7 / 1.2.5+
Fix from $1,950 2021-05-24
Control Center MEDIUM 5.5
CVE-2020-14391

A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal cr…

Mitigation only
Fix from $1,600 2021-02-08