VYPR

rpm package

almalinux/gvfs-fuse

pkg:rpm/almalinux/gvfs-fuse

Vulnerabilities (8)

  • CVE-2026-88924HigSep 10, 2026
    affected < 1.54.4-4.el10_2.1fixed 1.54.4-4.el10_2.1

    A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a T

  • CVE-2026-84268HigSep 1, 2026
    affected < 1.36.2-22.el8_10fixed 1.36.2-22.el8_10

    A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated

  • CVE-2020-13584HigDec 3, 2020
    affected < 1.36.2-11.el8fixed 1.36.2-11.el8

    An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in a remote code execution. The victim needs to visit a malicious web site to trigger this vulnerability.

  • CVE-2020-13543HigDec 3, 2020
    affected < 1.36.2-11.el8fixed 1.36.2-11.el8

    A code execution vulnerability exists in the WebSocket functionality of Webkit WebKitGTK 2.30.0. A specially crafted web page can trigger a use-after-free vulnerability which can lead to remote code execution. An attacker can get a user to visit a webpage to trigger this vulnerab

  • CVE-2020-9983HigOct 16, 2020
    affected < 1.36.2-11.el8fixed 1.36.2-11.el8

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to code execution.

  • CVE-2020-9951HigOct 16, 2020
    affected < 1.36.2-11.el8fixed 1.36.2-11.el8

    A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2020-9948HigOct 16, 2020
    affected < 1.36.2-11.el8fixed 1.36.2-11.el8

    A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2019-13012HigJun 28, 2019
    affected < 1.36.2-11.el8fixed 1.36.2-11.el8

    The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and files using g_file_replace_contents (kfsb->file, contents, length, NULL, FALSE, G_FILE_CREATE_REPLACE_DESTINATION, NULL,