Skip to main content

Vendor/product archive

gnome / gnome-shell CVEs

Beta · best-effort

11 CVEs tagged to gnome / gnome-shell0 Critical, 2 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2023-43090

Published Sep 22, 2023

A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3982

Published Apr 29, 2022

Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privilege permissions, may take advantage of the way C…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20315

Published Feb 18, 2022

A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are ena…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8288

Published Apr 27, 2017

gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander coul…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7221

Published Apr 29, 2014

The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Enter a Command" dialog, which allows physically proximate att…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7220

Published Apr 29, 2014

js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4427

Published Oct 1, 2012

The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a crafted web page.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4000

Published Nov 6, 2010

gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1