Skip to main content

Vendor/product archive

gnome / epiphany CVEs

Beta · best-effort

13 CVEs tagged to gnome / epiphany0 Critical, 6 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2021-45087

Published Dec 16, 2021

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45086

Published Dec 16, 2021

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45085

Published Dec 16, 2021

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-12016

Published Jun 7, 2018

libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via certain window.open and document.write cal…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11396

Published May 23, 2018

ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that tri…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000025

Published Jul 17, 2017

GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resultin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-3312

Published Oct 14, 2010

Epiphany 2.28 and 2.29, when WebKit and LibSoup are used, unconditionally displays a closed-lock icon for any URL beginning with the https: substring, without any warning to the u…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5985

Published Jan 28, 2009

Untrusted search path vulnerability in the Python interface in Epiphany 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1