Skip to main content

Vendor archive

gnome CVEs

Beta · best-effort

359 CVEs tagged to vendor gnome32 Critical, 115 High, 175 Medium, 37 Low, 0 Unrated.

CVE-2023-32665

Published Sep 14, 2023

A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of servi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32643

Published Sep 14, 2023

A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fix for CVE-2023-32665. This bug does not affect any released…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32636

Published Sep 14, 2023

A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. T…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32611

Published Sep 14, 2023

A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29499

Published Sep 14, 2023

A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36250

Published Sep 14, 2023

CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating a new record.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-25085

Published Dec 26, 2022

A vulnerability was found in GNOME gvdb. It has been classified as critical. This affects the function gvdb_table_write_contents_async of the file gvdb-builder.c. The manipulation…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-42522

Published Aug 25, 2022

There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrect use of libxml2 API. The vendor forgot…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3982

Published Apr 29, 2022

Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privilege permissions, may take advantage of the way C…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3567

Published Mar 25, 2022

A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that leverage Caribou as an input mech…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27811

Published Mar 24, 2022

GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-20315

Published Feb 18, 2022

A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are ena…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45087

Published Dec 16, 2021

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45086

Published Dec 16, 2021

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45085

Published Dec 16, 2021

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39365

Published Aug 22, 2021

In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attack…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39361

Published Aug 22, 2021

In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network M…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 359 CVEsPage 3 of 15