Skip to main content

Vendor/product archive

gnome / glib CVEs

Beta · best-effort

37 CVEs tagged to gnome / glib3 Critical, 13 High, 20 Medium, 1 Low, 0 Unrated.

CVE-2026-58016

Published Jun 30, 2026

A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML,…

CVSS 7.5 · High
evidence mentions
9
Buzz score
39.5
Vendor/product tagsBeta · best-effort

CVE-2026-58015

Published Jun 30, 2026

A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from t…

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-58014

Published Jun 30, 2026

A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This…

CVSS 7.3 · High
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-58013

Published Jun 30, 2026

A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-58012

Published Jun 30, 2026

A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because th…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-58011

Published Jun 30, 2026

A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produce…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2026-58010

Published Jun 30, 2026

A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because th…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2025-14087

Published Dec 10, 2025

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer…

CVSS 5.6 · Medium
evidence mentions
22
Buzz score
41.5
Vendor/product tagsBeta · best-effort

CVE-2025-4056

Published Jul 28, 2025

A flaw was found in GLib. A denial of service on Windows platforms may occur if an application attempts to spawn a program using long command lines.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-6052

Published Jun 13, 2025

A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in t…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-32665

Published Sep 14, 2023

A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of servi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32643

Published Sep 14, 2023

A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fix for CVE-2023-32665. This bug does not affect any released…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32636

Published Sep 14, 2023

A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. T…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32611

Published Sep 14, 2023

A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29499

Published Sep 14, 2023

A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35457

Published Dec 14, 2020

GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's position is "Realistically this is n…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6750

Published Jan 9, 2020

GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the pro…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 37 CVEsPage 1 of 2