VYPR

Vendor CVEs

GNOME Foundation

All CVEs

544 total · sorted by risk
  • CVE-2007-0999Mar 10, 2007
    risk 0.00cvss —epss 0.03

    Format string vulnerability in Ekiga 2.0.3, and probably other versions, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2007-1006.

  • CVE-2006-6698Dec 22, 2006
    risk 0.00cvss —epss 0.00

    The GConf daemon (gconfd) in GConf 2.14.0 creates temporary files under directories with names based on the username, even when GCONF_GLOBAL_LOCKS is not set, which allows local users to cause a denial of service by creating the directories ahead of time, which prevents other…

  • CVE-2006-6105Dec 15, 2006
    risk 0.00cvss —epss 0.00

    Format string vulnerability in the host chooser window (gdmchooser) in GNOME Foundation Display Manager (gdm) allows local users to execute arbitrary code via format string specifiers in a hostname, which are used in an error dialog.

  • CVE-2006-4514Nov 30, 2006
    risk 0.00cvss —epss 0.04

    Heap-based buffer overflow in the ole_info_read_metabat function in Gnome Structured File library (libgsf) 1.14.0, and other versions before 1.14.2, allows context-dependent attackers to execute arbitrary code via a large num_metabat value in an OLE document, which causes the…

  • CVE-2006-3057Jun 16, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in NetworkManager daemon for DHCP (dhcdbd) allows remote attackers to cause a denial of service (crash) via certain invalid DHCP responses that trigger memory corruption.

  • CVE-2006-2452Jun 9, 2006
    risk 0.00cvss —epss 0.00

    GNOME GDM 2.8, 2.12, 2.14, and 2.15, when the "face browser" feature is enabled, allows local users to access the "Configure Login Manager" functionality using their own password instead of the root password, which can be leveraged to gain additional privileges.

  • CVE-2006-2789Jun 2, 2006
    risk 0.00cvss —epss 0.02

    Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when "load images if sender in addressbook" is enabled, allows remote attackers to cause a denial of service (persistent crash) via a crafted "From" header that triggers an assert error in camel-internet-address.c when a null…

  • CVE-2006-1057Apr 25, 2006
    risk 0.00cvss —epss 0.00

    Race condition in daemon/slave.c in gdm before 2.14.1 allows local users to gain privileges via a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file.

  • CVE-2006-1335Mar 21, 2006
    risk 0.00cvss —epss 0.00

    gnome screensaver before 2.14, when running on an X server with AllowDeactivateGrabs and AllowClosedownGrabs enabled, allows attackers with physical access to cause the screensaver to crash and access the session via the Ctl+Alt+Keypad-Multiply keyboard sequence, which removes…

  • CVE-2006-1244Mar 15, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2)…

  • CVE-2006-0820Mar 13, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Dwarf HTTP Server 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified error messages.

  • CVE-2006-0819Mar 13, 2006
    risk 0.00cvss —epss 0.02

    Dwarf HTTP Server 1.3.2 allows remote attackers to obtain the source code of JSP files via (1) dot, (2) space, (3) slash, or (4) NULL characters in the filename extension of an HTTP request.

  • CVE-2006-0040Mar 10, 2006
    risk 0.00cvss —epss 0.02

    GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml.

  • CVE-2005-2976Nov 18, 2005
    risk 0.00cvss —epss 0.05

    Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a different vulnerability than CVE-2005-3186.

  • CVE-2005-2975Nov 18, 2005
    risk 0.00cvss —epss 0.04

    io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.

  • CVE-2005-3186Nov 18, 2005
    risk 0.00cvss —epss 0.05

    Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which leads to a heap-based buffer overflow.

  • CVE-2005-2958Oct 25, 2005
    risk 0.00cvss —epss 0.04

    Multiple format string vulnerabilities in the GNOME Data Access library for GNOME2 (libgda2) 1.2.1 and earlier allow attackers to execute arbitrary code.

  • CVE-2005-2944Sep 16, 2005
    risk 0.00cvss —epss 0.00

    The perform_file_save function in GNOME Workstation Command Center (gwcc) 0.9.6 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the gwcc_out.txt temporary file.

  • CVE-2005-2550Aug 12, 2005
    risk 0.00cvss —epss 0.04

    Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab.

  • CVE-2005-2549Aug 12, 2005
    risk 0.00cvss —epss 0.04

    Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.

  • CVE-2005-2410Aug 1, 2005
    risk 0.00cvss —epss 0.04

    Format string vulnerability in the nm_info_handler function in Network Manager may allow remote attackers to execute arbitrary code via format string specifiers in a Wireless Access Point identifier, which is not properly handled in a syslog call.

  • CVE-2005-0372May 2, 2005
    risk 0.00cvss —epss 0.04

    Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.

  • CVE-2005-0238May 2, 2005
    risk 0.00cvss —epss 0.02

    The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing…

  • CVE-2005-0206Apr 27, 2005
    risk 0.00cvss —epss 0.03

    The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.

  • CVE-2004-0889Jan 27, 2005
    risk 0.00cvss —epss 0.06

    Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.

  • CVE-2004-0494Nov 23, 2004
    risk 0.00cvss —epss 0.02

    Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI.

  • CVE-2004-0753Oct 20, 2004
    risk 0.00cvss —epss 0.06

    The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted BMP file.

  • CVE-2004-0788Oct 20, 2004
    risk 0.00cvss —epss 0.06

    Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted ICO file.

  • CVE-2004-0111Apr 15, 2004
    risk 0.00cvss —epss 0.02

    gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.

  • CVE-2003-0793Nov 17, 2003
    risk 0.00cvss —epss 0.00

    GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not restrict the size of input, which allows attackers to cause a denial of service (memory consumption).

  • CVE-2003-0794Nov 17, 2003
    risk 0.00cvss —epss 0.00

    GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not limit the number or duration of commands and uses a blocking socket connection, which allows attackers to cause a denial of service (resource exhaustion) by sending commands and not reading the results.

  • CVE-2003-0541Sep 17, 2003
    risk 0.00cvss —epss 0.03

    gtkhtml before 1.1.10, as used in Evolution, allows remote attackers to cause a denial of service (crash) via a malformed message that causes a null pointer dereference.

  • CVE-2003-0549Aug 27, 2003
    risk 0.00cvss —epss 0.01

    The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.

  • CVE-2003-0547Aug 27, 2003
    risk 0.00cvss —epss 0.00

    GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file.

  • CVE-2003-0548Aug 27, 2003
    risk 0.00cvss —epss 0.01

    The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.

  • CVE-2003-0133May 5, 2003
    risk 0.00cvss —epss 0.02

    GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.

  • CVE-2003-0080Mar 31, 2003
    risk 0.00cvss —epss 0.02

    The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass intended access restrictions if packet forwarding is enabled.

  • CVE-2003-0070Mar 3, 2003
    risk 0.00cvss —epss 0.02

    VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user…

  • CVE-2002-1765Dec 31, 2002
    risk 0.00cvss —epss 0.02

    Evolution 1.0.3 and 1.0.4 allows remote attackers to cause a denial of service (memory consumption and crash) via an email with a malformed MIME header.

  • CVE-2001-0928Nov 28, 2001
    risk 0.00cvss —epss 0.06

    Buffer overflow in the permitted function of GNOME gtop daemon (libgtop_daemon) in libgtop 1.0.13 and earlier may allow remote attackers to execute arbitrary code via long authentication data.

  • CVE-2001-0927Nov 27, 2001
    risk 0.00cvss —epss 0.03

    Format string vulnerability in the permitted function of GNOME libgtop_daemon in libgtop 1.0.12 and earlier allows remote attackers to execute arbitrary code via an argument that contains format specifiers that are passed into the (1) syslog_message and (2) syslog_io_message…

  • CVE-2000-0948Dec 19, 2000
    risk 0.00cvss —epss 0.00

    GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.

  • CVE-2000-0792Oct 20, 2000
    risk 0.00cvss —epss 0.01

    Gnome Lokkit firewall package before 0.41 does not properly restrict access to some ports, even if a user does not make any services available.

  • CVE-1999-0990Dec 5, 1999
    risk 0.00cvss —epss 0.00

    Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.

Page 11 of 11