Skip to main content

Vendor archive

gnome CVEs

Beta · best-effort

359 CVEs tagged to vendor gnome32 Critical, 115 High, 175 Medium, 37 Low, 0 Unrated.

CVE-2026-1536

Published Jan 28, 2026

A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value.…

CVSS 5.8 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-1467

Published Jan 27, 2026

A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the libra…

CVSS 5.8 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-14087

Published Dec 10, 2025

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer…

CVSS 5.6 · Medium
evidence mentions
22
Buzz score
41.5
Vendor/product tagsBeta · best-effort

CVE-2025-4056

Published Jul 28, 2025

A flaw was found in GLib. A denial of service on Windows platforms may occur if an application attempts to spawn a program using long command lines.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-6199

Published Jun 17, 2025

A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full bu…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-6196

Published Jun 17, 2025

A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB files, leading to incorrect mem…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-6052

Published Jun 13, 2025

A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in t…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-43091

Published Nov 17, 2024

A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-52532

Published Nov 11, 2024

GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52531

Published Nov 11, 2024

GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52530

Published Nov 11, 2024

GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: chunk…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42415

Published Oct 3, 2024

An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Library (libgsf). A specially crafte…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36474

Published Oct 3, 2024

An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) version v1.14.52. A specially c…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36774

Published Feb 19, 2024

plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to a denial of service (application crash).

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-48622

Published Jan 26, 2024

In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in ani_load_chunk in io-ani.c) when parsing chunk…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43090

Published Sep 22, 2023

A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-50 of 359 CVEsPage 2 of 15