VYPR

Vendor CVEs

GNOME Foundation

All CVEs

545 total · sorted by risk
  • CVE-2024-58377MedAug 25, 2026
    risk 0.29cvss 5.5epss 0.00

    Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. Nokogiri 1.16.5 upgrades the bundled libxml2 to 2.12.7 to address this. Per the maintainers, there is no impact to Nokogiri users because Nokogiri does not…

  • CVE-2025-14087MedDec 10, 2025
    risk 0.29cvss 5.6epss 0.01

    A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.

  • CVE-2020-36774MedFeb 19, 2024
    risk 0.29cvss 5.5epss 0.00

    plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to a denial of service (application crash).

  • CVE-2023-43090MedSep 22, 2023
    risk 0.29cvss 5.5epss 0.00

    A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.

  • CVE-2023-38633MedJul 22, 2023
    risk 0.29cvss 5.5epss 0.02

    A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include…

  • CVE-2020-36427MedJul 19, 2021
    risk 0.29cvss 5.5epss 0.01

    GNOME gThumb before 3.10.1 allows an application crash via a malformed JPEG image.

  • CVE-2021-20297MedMay 26, 2021
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.

  • CVE-2020-36241MedFeb 5, 2021
    risk 0.29cvss 5.5epss 0.01

    autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

  • CVE-2012-2736MedDec 26, 2019
    risk 0.29cvss 4.4epss 0.00

    In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.

  • CVE-2026-10028MedMay 28, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting a specially crafted certificate chain to an application that uses glib-networking with the GnuTLS backend enabled and performs certificate verification. This crafted chain, which…

  • CVE-2025-4476MedMay 16, 2025
    risk 0.28cvss 4.3epss 0.00

    A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header.…

  • CVE-2025-4035MedApr 29, 2025
    risk 0.28cvss 4.3epss 0.00

    A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections and could allow a…

  • CVE-2024-38394MedJun 16, 2024
    risk 0.28cvss 4.3epss 0.00

    Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB…

  • CVE-2020-17489MedAug 11, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time,…

  • CVE-2020-10754MedJun 8, 2020
    risk 0.28cvss 4.3epss 0.01

    It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made…

  • CVE-2019-3820MedFeb 6, 2019
    risk 0.28cvss 4.3epss 0.01

    It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.

  • CVE-2026-1484MedJan 27, 2026
    risk 0.27cvss 4.2epss 0.00

    A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications…

  • CVE-2017-12164MedJul 26, 2018
    risk 0.27cvss 4.1epss 0.00

    A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as another user' to unlock their screen.

  • CVE-2026-3634LowMar 17, 2026
    risk 0.25cvss 3.9epss 0.00

    A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. This vulnerability allows for…

  • CVE-2026-3633LowMar 17, 2026
    risk 0.25cvss 3.9epss 0.00

    A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF (Carriage Return Line Feed) injection, occurs because the…

  • CVE-2026-3632LowMar 17, 2026
    risk 0.25cvss 3.9epss 0.00

    A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP headers. A remote attacker could exploit this to perform…

  • CVE-2026-81893MedAug 27, 2026
    risk 0.24cvss 4.7epss 0.00

    A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an…

  • CVE-2026-2708LowApr 23, 2026
    risk 0.24cvss 3.7epss 0.00

    A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields.…

  • CVE-2026-0988LowJan 21, 2026
    risk 0.24cvss 3.7epss 0.00

    A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being…

  • CVE-2026-0989LowJan 15, 2026
    risk 0.24cvss 3.7epss 0.01

    A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested directives. Specially crafted or overly complex schemas can cause excessive…

  • CVE-2025-60019LowSep 25, 2025
    risk 0.24cvss 3.7epss 0.00

    glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location.

  • CVE-2025-3360LowApr 7, 2025
    risk 0.24cvss 3.7epss 0.00

    A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.

  • CVE-2016-1000033LowOct 25, 2016
    risk 0.24cvss 3.7epss 0.01

    Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.

  • CVE-2024-37535MedJun 9, 2024
    risk 0.22cvss 4.4epss 0.00

    GNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape sequence, a related issue to CVE-2000-0476.

  • CVE-2026-84270MedSep 1, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data length returned by the device without limiting it to the original size requested by the client. If a malicious MTP device responds with more…

  • CVE-2026-84267MedSep 1, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the function does not verify that the buffer is completely filled, leaving the remainder of the buffer containing…

  • CVE-2025-6199LowJun 17, 2025
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in…

  • CVE-2021-3349LowFeb 1, 2021
    risk 0.21cvss 3.3epss 0.00

    GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether…

  • CVE-2019-16680MedSep 21, 2019
    risk 0.21cvss 4.3epss 0.02

    An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.

  • CVE-2025-11731LowOct 14, 2025
    risk 0.20cvss 3.1epss 0.00

    A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This…

  • CVE-2026-0992LowJan 15, 2026
    risk 0.19cvss 2.9epss 0.00

    A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted…

  • CVE-2026-1485LowJan 27, 2026
    risk 0.18cvss 2.8epss 0.00

    A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds…

  • CVE-2020-36314LowApr 7, 2021
    risk 0.18cvss 3.9epss 0.01

    fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of…

  • CVE-2025-6052LowJun 13, 2025
    risk 0.17cvss 3.7epss 0.01

    A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a…

  • CVE-2016-1000002LowNov 5, 2019
    risk 0.16cvss 2.4epss 0.01

    gdm3 3.14.2 and possibly later has an information leak before screen lock

  • CVE-2025-8732LowAug 8, 2025
    risk 0.14cvss 3.3epss 0.00

    A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has…

  • CVE-2026-86141LowSep 5, 2026
    risk 0.12cvss 2.9epss 0.00

    xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.

  • CVE-2026-86137LowSep 5, 2026
    risk 0.12cvss 2.9epss 0.00

    In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.

  • CVE-2008-3533Aug 18, 2008
    risk 0.05cvss —epss 0.19

    Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to execute arbitrary code via format string specifiers in an invalid URI on the command line, as demonstrated by use of yelp within…

  • CVE-2013-5745Oct 1, 2013
    risk 0.04cvss —epss 0.09

    The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authentication, which allows remote…

  • CVE-2012-2738Jul 22, 2012
    risk 0.04cvss —epss 0.11

    The VteTerminal in gnome-terminal (vte) before 0.32.2 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value.

  • CVE-2008-5660Dec 17, 2008
    risk 0.04cvss —epss 0.09

    Format string vulnerability in the vinagre_utils_show_error function (src/vinagre-utils.c) in Vinagre 0.5.x before 0.5.2 and 2.x before 2.24.2 might allow remote attackers to execute arbitrary code via format string specifiers in a crafted URI or VNC server response.

  • CVE-2006-0528Feb 2, 2006
    risk 0.04cvss —epss 0.11

    The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the…

  • CVE-2005-1686May 20, 2005
    risk 0.04cvss —epss 0.08

    Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename. NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that…

  • CVE-2003-0407Jun 30, 2003
    risk 0.04cvss —epss 0.16

    Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.

Page 7 of 11