Search

Found 63 results in 23ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-5119 medium 5.9 5.9 FIX rheldebian debian sles gnome 29d ago A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network…
CVE-2026-2708 medium 5.3 5.3 debian debian sles rhel gnome 1mo ago A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each hea…
CVE-2026-2369 critical 9.1 9.1 FIX debian debian sles gnome 3mo ago A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially acc…
CVE-2025-14512 medium 6.5 6.5 FIX rheldebian debian sles gnomeredhat 6mo ago A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when pro…
CVE-2025-14087 medium 5.6 5.6 FIX rheldebian debian sles gnome 6mo ago A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GV…
CVE-2024-34397 medium 5.2 5.2 FIX rhel rockydebian debian gnomenetapp 2y ago RHSA-2025:11327: glib2 security update (Moderate)
CVE-2017-14604 medium 6.5 6.5 FIX slesdebian debian gnome 9y ago GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .desktop file's Name field ends in .pdf but this file…
CVE-2017-14108 medium 5.5 5.5 slesdebian debian gnome 9y ago libgedit.a in GNOME gedit through 3.22.1 allows remote attackers to cause a denial of service (CPU consumption) via a file that begins with many '\0' characters.
CVE-2017-1000044 critical 9.8 9.8 FIX debian debian gnome 9y ago gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when rendering
CVE-2017-11171 medium 5.5 5.5 FIX slesdebian debian gnome 9y ago Bad reference counting in the context of accept_ice_connection() in gsm-xsmp-server.c in old versions of gnome-session up until version 2.29.92 allows a local attacker to establish ICE connections to…
CVE-2017-8871 medium 6.5 7.5 EXP slessuse suse gnome 9y ago The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file.
CVE-2017-8834 medium 6.5 6.5 slessuse suse gnome 9y ago The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (memory allocation error) via a crafted CSS file.
CVE-2017-7960 medium 5.5 5.5 sles gnome 9y ago The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.
CVE-2017-6314 medium 5.5 5.5 FIX slesdebian debianfedora fedora gnome 9y ago The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (infinite loop) via a large TIFF file.
CVE-2017-6312 medium 5.5 5.5 FIX slesdebian debianfedora fedora gnome 9y ago Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, …
CVE-2017-5885 critical 9.8 9.8 FIX slesdebian debianfedora fedora gnome 9y ago Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly e…
CVE-2016-6163 medium 5.5 5.5 FIX slesdebian debian gnome 10y ago The rsvg_pattern_fix_fallback function in rsvg-paint_server.c in librsvg2 2.40.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted svg file.
CVE-2016-9888 medium 5.5 5.5 FIX slesdebian debian gnome 10y ago An error within the "tar_directory_for_file()" function (gsf-infile-tar.c) in GNOME Structured File Library before 1.14.41 can be exploited to trigger a Null pointer dereference and subsequently caus…
CVE-2015-7217 medium 4.3 suse susefedora fedora mozillagnome 11y ago The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the TGA decoder, which allows remote attackers to cause a denial of service (heap-based buffer…
CVE-2015-7216 medium 6.8 suse susefedora fedora mozillagnome 11y ago The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote attackers to cause a denial of service or possibly hav…
CVE-2015-0272 medium 5.0 FIX debian debianubuntu ubuntususe suse gnomesuse 11y ago GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message, a different vulnerability tha…
CVE-2015-7674 medium 6.8 FIX debian debianubuntu ubuntususe suse gnome 11y ago Integer overflow in the pixops_scale_nearest function in pixops/pixops.c in gdk-pixbuf before 2.32.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbi…
CVE-2015-7673 medium 6.8 FIX debian debiansuse suse gnome 11y ago io-tga.c in gdk-pixbuf before 2.32.0 uses heap memory after its allocation failed, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) and po…
CVE-2015-4491 medium 6.8 FIX slesdebian debianubuntu ubuntu gnomegooglemozilla 11y ago Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on L…
CVE-2015-0552 medium 6.4 FIX debian debiansuse suse gnome 12y ago Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder.c in gcab 0.4 allows remote attackers to write to arbitrary files via crafted path in a CAB file, as demon…
CVE-2013-7221 medium 4.6 FIX debian debian gnome 12y ago The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Enter a Command" dialog, which allows physically proximate attackers to execute ar…
CVE-2013-7220 medium 4.6 FIX debian debian gnome 12y ago js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with the keyboard focus o…
CVE-2013-6836 medium 4.3 FIX debian debian gnome 13y ago Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a cr…
CVE-2013-1978 medium 6.8 FIX debian debian rhel gimpgnome 13y ago Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and po…
CVE-2013-1913 medium 6.8 FIX debian debian rhel gimpgnome 13y ago Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.24, allows remote attackers to cause a denial of s…
CVE-2013-1881 medium 4.3 FIX debian debian gnome 13y ago GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML Ext…
CVE-2013-4169 medium 6.9 FIX debian debian gnome 13y ago GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/.
CVE-2013-1799 medium 4.3 FIX debian debianubuntu ubuntu gnome 13y ago Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-…
CVE-2013-0240 medium 4.3 FIX debian debianubuntu ubuntu gnome 13y ago Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which all…
CVE-2011-3201 medium 4.3 debian debian rhel gnome 13y ago GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.
CVE-2011-5244 medium 6.8 FIX debian debian gnomet1libtetex 14y ago Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote at…
CVE-2011-0433 medium 6.8 FIX debian debian gnomet1libtetex 14y ago Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (c…
CVE-2012-4511 medium 5.8 gnome 14y ago services/flickr/flickr.c in libsocialweb before 0.25.21 automatically connects to Flickr when no Flickr account is set, which might allow remote attackers to obtain sensitive information via a man-in…
CVE-2012-3466 medium 4.4 FIX debian debian gnome 14y ago GNOME gnome-keyring 3.4.0 through 3.4.1, when gpg-cache-method is set to "idle" or "timeout," does not properly limit the amount of time a passphrase is cached, which allows attackers to have an unsp…
CVE-2011-4129 medium 5.8 gnome 14y ago (1) services/twitter/twitter-contact-view.c and (2) services/twitter/twitter-item-view.c in libsocialweb before 0.25.20 automatically connect to Twitter when no Twitter account is set, which might al…
CVE-2012-4427 medium 6.8 FIX debian debian gnome 14y ago The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a crafted web page.
CVE-2011-3146 medium 6.8 FIX debian debian gnome 14y ago librsvg before 2.34.1 uses the node name to identify the type of node, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference) and possibly execute arbitrary …
CVE-2012-1177 medium 5.1 FIX debian debian gnome 14y ago libgdata before 0.10.2 and 0.11.x before 0.11.1 does not validate SSL certificates, which allows remote attackers to obtain user names and passwords via a man-in-the-middle (MITM) attack with a spoof…
CVE-2012-2132 medium 5.0 debian debian gnome 14y ago libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL …
CVE-2012-2370 medium 5.0 FIX debian debian gnome 14y ago Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in gdk-pixbuf before 2.26.1 allow remote attackers to cause a denial of service (application crash) via a negative (1) hei…
CVE-2011-2485 medium 4.3 FIX debian debian gnome 14y ago The gdk_pixbuf__gif_image_load function in gdk-pixbuf/io-gif.c in gdk-pixbuf before 2.23.5 does not properly handle certain return values, which allows remote attackers to cause a denial of service (…
CVE-2011-3193 critical 9.3 FIX suse suse rhelubuntu ubuntu gnomeqt 14y ago Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (cra…
CVE-2011-3364 medium 6.9 FIX debian debian gnome 15y ago Incomplete blacklist vulnerability in the svEscape function in settings/plugins/ifcfg-rh/shvar.c in the ifcfg-rh plug-in for GNOME NetworkManager 0.9.1, 0.9.0, 0.8.1, and possibly other versions, whe…
CVE-2011-4170 medium 4.3 FIX debian debian gnome 15y ago Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows remote attackers …
CVE-2011-3635 medium 4.3 FIX debian debian gnome 15y ago Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows remote attackers …
CVE-2010-4833 critical 9.3 FIX debian debian gnome 15y ago Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan horse uxtheme.dll file in the current working dir…
CVE-2010-4831 medium 6.9 FIX debian debian gnome 15y ago Untrusted search path vulnerability in gdk/win32/gdkinput-win32.c in GTK+ before 2.21.8 allows local users to gain privileges via a Trojan horse Wintab32.dll file in the current working directory.
CVE-2011-2524 medium 5.0 FIX debian debian gnome 15y ago Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI.
CVE-2011-0727 medium 6.9 FIX debian debian gnome 15y ago GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/.
CVE-2011-0064 medium 6.8 FIX debian debian gnomemozilla 16y ago The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote attackers to cau…
CVE-2010-4005 medium 6.9 gnome 16y ago The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse…
CVE-2010-4000 medium 6.9 FIX debian debian gnome 16y ago gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working dire…
CVE-2010-3312 medium 5.8 FIX debian debian gnome 16y ago Epiphany 2.28 and 2.29, when WebKit and LibSoup are used, unconditionally displays a closed-lock icon for any URL beginning with the https: substring, without any warning to the user, which allows ma…
CVE-2010-2713 medium 6.8 FIX debian debian nalin_dahyabhaignome 16y ago The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows…
CVE-2010-0732 medium 6.2 FIX debian debian gnome 16y ago gdk/gdkwindow.c in GTK+ before 2.18.5, as used in gnome-screensaver before 2.28.1, performs implicit paints on windows of type GDK_WINDOW_FOREIGN, which triggers an X error in certain circumstances a…
CVE-2010-0421 medium 4.3 FIX debian debian gnome 16y ago Array index error in the hb_ot_layout_build_glyph_classes function in pango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows context-dependent attackers to cause a denial of service (applicatio…
CVE-2010-0422 medium 4.0 FIX debian debian gnome 17y ago gnome-screensaver 2.28.x before 2.28.3 does not properly synchronize the state of screen locking and the unlock dialog in situations involving a change to the number of monitors, which allows physica…
CVE-2010-0285 medium 5.6 FIX debian debian gnome 17y ago gnome-screensaver 2.14.3, 2.22.2, 2.27.x, 2.28.0, and 2.28.3, when the X configuration enables the extend screen option, allows physically proximate attackers to bypass screen locking, access an unat…