Skip to main content

Vendor archive

gnome CVEs

Beta · best-effort

359 CVEs tagged to vendor gnome32 Critical, 115 High, 175 Medium, 37 Low, 0 Unrated.

CVE-2008-7185

Published Sep 8, 2009

GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlist (.pls) file with a long Title field, possibly related to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2697

Published Sep 4, 2009

The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1631

Published May 14, 2009

The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to l…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-1276

Published Apr 9, 2009

XScreenSaver in Sun Solaris 10 and OpenSolaris before snv_109, and Solaris 8 and 9 with GNOME 2.0 or 2.0.2, allows physically proximate attackers to obtain sensitive information b…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-0582

Published Mar 14, 2009

The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier,…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4316

Published Mar 14, 2009

Multiple integer overflows in glib/gbase64.c in GLib before 2.20 allow context-dependent attackers to execute arbitrary code via a long string that is converted either (1) from or…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0318

Published Jan 28, 2009

Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the curren…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0317

Published Jan 28, 2009

Untrusted search path vulnerability in the Python language bindings for Nautilus (nautilus-python) allows local users to execute arbitrary code via a Trojan horse Python file in t…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0314

Published Jan 28, 2009

Untrusted search path vulnerability in the Python module in gedit allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, rel…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5987

Published Jan 28, 2009

Untrusted search path vulnerability in the Python interface in Eye of GNOME (eog) 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a Trojan ho…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5985

Published Jan 28, 2009

Untrusted search path vulnerability in the Python interface in Epiphany 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5660

Published Dec 17, 2008

Format string vulnerability in the vinagre_utils_show_error function (src/vinagre-utils.c) in Vinagre 0.5.x before 0.5.2 and 2.x before 2.24.2 might allow remote attackers to exec…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3533

Published Aug 18, 2008

Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to execute arbitrary code via form…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-1108

Published Jun 4, 2008

Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attac…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1109

Published Jun 4, 2008

Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar attachment, which is…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0887

Published Apr 6, 2008

gnome-screensaver before 2.22.1, when a remote authentication server is enabled, crashes upon an unlock attempt during a network outage, which allows physically proximate attacker…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0072

Published Mar 6, 2008

Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to execute arbitrary code via a cra…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0668

Published Feb 11, 2008

The excel_read_HLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6389

Published Dec 17, 2007

The notify feature in GNOME screensaver (gnome-screensaver) 2.20.0 might allow local users to read the clipboard contents and X selection data for a locked session by using ctrl-V.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-5007

Published Dec 12, 2007

Stack-based buffer overflow in the ir_fetch_seq function in balsa before 2.3.20 might allow remote IMAP servers to execute arbitrary code via a long response to a FETCH command.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 359 CVEsPage 12 of 15