VYPR

Vendor CVEs

GNOME Foundation

All CVEs

544 total · sorted by risk
  • CVE-2026-91786MedSep 15, 2026
    risk 0.40cvss 6.1epss 0.00

    A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared dimensions against the actual data buffer size. A malicious or compromised remote search provider could exploit this by providing…

  • CVE-2026-18090MedSep 8, 2026
    risk 0.40cvss 6.1epss 0.00

    A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source…

  • CVE-2026-82343MedAug 28, 2026
    risk 0.40cvss 6.1epss 0.00

    A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads to improper memory bounds checking, resulting in both a heap out-of-bounds read…

  • CVE-2026-82330MedAug 28, 2026
    risk 0.40cvss 6.1epss 0.00

    A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an…

  • CVE-2026-82328MedAug 28, 2026
    risk 0.40cvss 6.1epss 0.00

    A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap…

  • CVE-2026-82324MedAug 28, 2026
    risk 0.40cvss 6.1epss 0.00

    A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color planes (nPlanes) is zero. This causes a row size…

  • CVE-2026-1757MedFeb 2, 2026
    risk 0.40cvss 6.2epss 0.00

    A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command…

  • CVE-2025-6035MedJun 13, 2025
    risk 0.40cvss 6.1epss 0.01

    A flaw was found in GIMP. An integer overflow vulnerability exists in the GIMP "Despeckle" plug-in. The issue occurs due to unchecked multiplication of image dimensions, such as width, height, and bytes-per-pixel (img_bpp), which can result in allocating insufficient memory and…

  • CVE-2021-45088MedDec 16, 2021
    risk 0.40cvss 6.1epss 0.01

    XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.

  • CVE-2021-45087MedDec 16, 2021
    risk 0.40cvss 6.1epss 0.01

    XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.

  • CVE-2021-45086MedDec 16, 2021
    risk 0.40cvss 6.1epss 0.01

    XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.

  • CVE-2021-45085MedDec 16, 2021
    risk 0.40cvss 6.1epss 0.01

    XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.

  • CVE-2026-13601HigJun 29, 2026
    risk 0.39cvss 7.1epss 0.00

    A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG…

  • CVE-2020-16117MedJul 29, 2020
    risk 0.39cvss 5.9epss 0.02

    In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.

  • CVE-2020-14928MedJul 17, 2020
    risk 0.39cvss 5.9epss 0.03

    evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."

  • CVE-2012-1096MedMar 10, 2020
    risk 0.39cvss 5.5epss 0.01

    NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.

  • CVE-2020-6750MedJan 9, 2020
    risk 0.39cvss 5.9epss 0.02

    GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending…

  • CVE-2019-3827HigMar 25, 2019
    risk 0.39cvss 7.0epss 0.00

    An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious…

  • CVE-2018-15120MedAug 24, 2018
    risk 0.39cvss 6.5epss 0.12

    libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.

  • CVE-2017-17689MedMay 16, 2018
    risk 0.39cvss 5.9epss 0.04

    The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

  • CVE-2026-86143MedSep 5, 2026
    risk 0.38cvss 6.9epss 0.00

    In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that…

  • CVE-2026-86142MedSep 5, 2026
    risk 0.38cvss 6.9epss 0.00

    In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.

  • CVE-2026-86139MedSep 5, 2026
    risk 0.38cvss 6.9epss 0.00

    In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

  • CVE-2026-86138MedSep 5, 2026
    risk 0.38cvss 6.9epss 0.00

    In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.

  • CVE-2026-85534MedSep 4, 2026
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered…

  • CVE-2026-15713MedJul 14, 2026
    risk 0.38cvss 5.9epss 0.01

    A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory context blocks under specific stream termination conditions, such as when an HTTP/2 connection encounters window exhaustion or explicit stream resets. A remote,…

  • CVE-2026-15712MedJul 14, 2026
    risk 0.38cvss 5.9epss 0.01

    A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the library processes an HTTP/2 GOAWAY frame, it improperly handles the "Additional Debug Data" payload by assuming the data stream is a…

  • CVE-2026-5119MedMar 30, 2026
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies,…

  • CVE-2026-3099MedMar 12, 2026
    risk 0.38cvss 5.8epss 0.00

    A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required incrementing nonce-count (nc) attribute. This vulnerability allows a remote attacker to capture a…

  • CVE-2026-1539MedJan 28, 2026
    risk 0.38cvss 5.8epss 0.00

    A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is…

  • CVE-2026-1536MedJan 28, 2026
    risk 0.38cvss 5.8epss 0.00

    A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed,…

  • CVE-2026-1467MedJan 27, 2026
    risk 0.38cvss 5.8epss 0.00

    A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. A remote attacker can…

  • CVE-2026-0990MedJan 15, 2026
    risk 0.38cvss 5.9epss 0.01

    A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent…

  • CVE-2025-9901MedSep 3, 2025
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored when evaluating cached responses. This header ensures that responses vary appropriately based on request headers such as language or authentication. Without this check, cached…

  • CVE-2025-32051MedApr 3, 2025
    risk 0.38cvss 5.9epss 0.01

    A flaw was found in libsoup. The libsoup soup_uri_decode_data_uri() function may crash when processing malformed data URI. This flaw allows an attacker to cause a denial of service (DoS).

  • CVE-2025-32050MedApr 3, 2025
    risk 0.38cvss 5.9epss 0.01

    A flaw was found in libsoup. The libsoup append_param_quoted() function may contain an overflow bug resulting in a buffer under-read.

  • CVE-2021-39365MedAug 22, 2021
    risk 0.38cvss 5.9epss 0.01

    In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

  • CVE-2021-39361MedAug 22, 2021
    risk 0.38cvss 5.9epss 0.01

    In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

  • CVE-2021-39360MedAug 22, 2021
    risk 0.38cvss 5.9epss 0.01

    In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

  • CVE-2021-39359MedAug 22, 2021
    risk 0.38cvss 5.9epss 0.01

    In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

  • CVE-2021-39358MedAug 22, 2021
    risk 0.38cvss 5.9epss 0.01

    In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

  • CVE-2020-24661MedAug 26, 2020
    risk 0.38cvss 5.9epss 0.01

    GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system-provided PKCS#11 store. This allows a meddler in the…

  • CVE-2011-1830MedApr 22, 2019
    risk 0.37cvss 5.7epss 0.01

    Ekiga versions before 3.3.0 attempted to load a module from /tmp/ekiga_test.so.

  • CVE-2026-1767MedJun 16, 2026
    risk 0.36cvss 5.6epss 0.00

    A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This…

  • CVE-2026-1766MedJun 16, 2026
    risk 0.36cvss 5.6epss 0.00

    A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment)…

  • CVE-2026-1765MedJun 16, 2026
    risk 0.36cvss 5.6epss 0.00

    A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3…

  • CVE-2026-1764MedJun 16, 2026
    risk 0.36cvss 5.6epss 0.00

    A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability…

  • CVE-2025-10911MedSep 25, 2025
    risk 0.36cvss 5.5epss 0.00

    A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.

  • CVE-2025-6196MedJun 17, 2025
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB files, leading to incorrect memory allocations. This issue causes the application to crash. Known affected usage includes desktop…

  • CVE-2025-32414MedApr 8, 2025
    risk 0.36cvss 5.6epss 0.00

    In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xmlPythonFileRead and xmlPythonFileReadRaw because of a difference between bytes and characters.

Page 5 of 11