gnome CVE Vulnerabilities & Metrics

Focus on gnome vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About gnome Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with gnome. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total gnome CVEs: 163
Earliest CVE date: 23 Sep 1999, 04:00 UTC
Latest CVE date: 03 Oct 2024, 16:15 UTC

Latest CVE reference: CVE-2024-42415

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 2

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -80.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -80.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical gnome CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.03

Max CVSS: 10.0

Critical CVEs (≥9): 9

CVSS Range vs. Count

Range Count
0.0-3.9 62
4.0-6.9 175
7.0-8.9 48
9.0-10.0 9

CVSS Distribution Chart

Top 5 Highest CVSS gnome CVEs

These are the five CVEs with the highest CVSS scores for gnome, sorted by severity first and recency.

All CVEs for gnome

CVE-2024-42415 gnome vulnerability CVSS: 0 03 Oct 2024, 16:15 UTC

An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Library (libgsf). A specially crafted file can result in an integer overflow that allows for a heap-based buffer overflow when processing the sector allocation table. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-36474 gnome vulnerability CVSS: 0 03 Oct 2024, 16:15 UTC

An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) version v1.14.52. A specially crafted file can result in an integer overflow when processing the directory from the file that allows for an out-of-bounds index to be used when reading and writing to an array. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-48622 gnome vulnerability CVSS: 0 26 Jan 2024, 09:15 UTC

In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in ani_load_chunk in io-ani.c) when parsing chunks in a crafted .ani file. A crafted file could allow an attacker to overwrite heap metadata, leading to a denial of service or code execution attack. This occurs in gdk_pixbuf_set_option() in gdk-pixbuf.c.

CVE-2023-5557 gnome vulnerability CVSS: 0 13 Oct 2023, 02:15 UTC

A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.

CVE-2023-43090 gnome vulnerability CVSS: 0 22 Sep 2023, 06:15 UTC

A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.

CVE-2023-32665 gnome vulnerability CVSS: 0 14 Sep 2023, 20:15 UTC

A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service.

CVE-2023-32643 gnome vulnerability CVSS: 0 14 Sep 2023, 20:15 UTC

A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fix for CVE-2023-32665. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-32665.

CVE-2023-32636 gnome vulnerability CVSS: 0 14 Sep 2023, 20:15 UTC

A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.

CVE-2023-32611 gnome vulnerability CVSS: 0 14 Sep 2023, 20:15 UTC

A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.

CVE-2023-29499 gnome vulnerability CVSS: 0 14 Sep 2023, 20:15 UTC

A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.

CVE-2023-36250 gnome vulnerability CVSS: 0 14 Sep 2023, 17:15 UTC

CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating a new record.

CVE-2023-38633 gnome vulnerability CVSS: 0 22 Jul 2023, 17:15 UTC

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

CVE-2023-26081 gnome vulnerability CVSS: 0 20 Feb 2023, 03:15 UTC

In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.

CVE-2019-25085 gnome vulnerability CVSS: 0 26 Dec 2022, 07:15 UTC

A vulnerability was found in GNOME gvdb. It has been classified as critical. This affects the function gvdb_table_write_contents_async of the file gvdb-builder.c. The manipulation leads to use after free. It is possible to initiate the attack remotely. The name of the patch is d83587b2a364eb9a9a53be7e6a708074e252de14. It is recommended to apply a patch to fix this issue. The identifier VDB-216789 was assigned to this vulnerability.

CVE-2022-37290 gnome vulnerability CVSS: 0 14 Nov 2022, 08:15 UTC

GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive.

CVE-2021-42522 gnome vulnerability CVSS: 0 25 Aug 2022, 18:15 UTC

There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrect use of libxml2 API. The vendor forgot to call 'g_free()' to release the return value of 'xmlGetProp()'.

CVE-2021-3800 gnome vulnerability CVSS: 0 23 Aug 2022, 16:15 UTC

A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.

CVE-2021-46829 gnome vulnerability CVSS: 0 24 Jul 2022, 19:15 UTC

GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.

CVE-2021-3982 gnome vulnerability CVSS: 2.1 29 Apr 2022, 17:15 UTC

Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privilege permissions, may take advantage of the way CAP_SYS_NICE is currently implemented and eventually load code to increase its process scheduler priority leading to possible DoS of other services running in the same machine.

CVE-2022-29536 gnome vulnerability CVSS: 5.0 20 Apr 2022, 23:15 UTC

In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered.

CVE-2022-27811 gnome vulnerability CVSS: 7.5 24 Mar 2022, 03:15 UTC

GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.

CVE-2021-20315 gnome vulnerability CVSS: 3.6 18 Feb 2022, 18:15 UTC

A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enabled. This flaw allows a physical attacker who has access to a locked system to kill existing applications and start new ones as the locked user, even if the session is still locked.

CVE-2021-44648 gnome vulnerability CVSS: 6.8 12 Jan 2022, 13:15 UTC

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.

CVE-2021-45088 gnome vulnerability CVSS: 4.3 16 Dec 2021, 03:15 UTC

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.

CVE-2021-45087 gnome vulnerability CVSS: 4.3 16 Dec 2021, 03:15 UTC

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.

CVE-2021-45086 gnome vulnerability CVSS: 4.3 16 Dec 2021, 03:15 UTC

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.

CVE-2021-45085 gnome vulnerability CVSS: 4.3 16 Dec 2021, 03:15 UTC

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.

CVE-2021-39365 gnome vulnerability CVSS: 4.3 22 Aug 2021, 22:15 UTC

In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

CVE-2021-39361 gnome vulnerability CVSS: 4.3 22 Aug 2021, 19:15 UTC

In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

CVE-2021-39360 gnome vulnerability CVSS: 4.3 22 Aug 2021, 19:15 UTC

In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

CVE-2021-39359 gnome vulnerability CVSS: 4.3 22 Aug 2021, 19:15 UTC

In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

CVE-2021-39358 gnome vulnerability CVSS: 4.3 22 Aug 2021, 19:15 UTC

In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

CVE-2020-36427 gnome vulnerability CVSS: 4.3 19 Jul 2021, 17:15 UTC

GNOME gThumb before 3.10.1 allows an application crash via a malformed JPEG image.

CVE-2021-20240 gnome vulnerability CVSS: 8.3 28 May 2021, 11:15 UTC

A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victim system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2009-3721 gnome vulnerability CVSS: 6.8 26 May 2021, 22:15 UTC

Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.

CVE-2021-20297 gnome vulnerability CVSS: 2.1 26 May 2021, 21:15 UTC

A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.

CVE-2016-20011 gnome vulnerability CVSS: 5.0 25 May 2021, 21:15 UTC

libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.

CVE-2021-33516 gnome vulnerability CVSS: 5.8 24 May 2021, 15:15 UTC

An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.

CVE-2020-36314 gnome vulnerability CVSS: 2.6 07 Apr 2021, 12:15 UTC

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

CVE-2021-28650 gnome vulnerability CVSS: 2.1 17 Mar 2021, 06:15 UTC

autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-36241.

CVE-2021-28153 gnome vulnerability CVSS: 5.0 11 Mar 2021, 22:15 UTC

An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.)

CVE-2021-27219 gnome vulnerability CVSS: 5.0 15 Feb 2021, 17:15 UTC

An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption.

CVE-2021-27218 gnome vulnerability CVSS: 5.0 15 Feb 2021, 17:15 UTC

An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing unintended length truncation.

CVE-2020-14391 gnome vulnerability CVSS: 2.1 08 Feb 2021, 23:15 UTC

A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.

CVE-2020-36241 gnome vulnerability CVSS: 2.1 05 Feb 2021, 14:15 UTC

autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

CVE-2021-3349 gnome vulnerability CVSS: 2.1 01 Feb 2021, 05:15 UTC

GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior

CVE-2020-27837 gnome vulnerability CVSS: 4.4 28 Dec 2020, 19:15 UTC

A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to exploit.

CVE-2020-29385 gnome vulnerability CVSS: 4.3 26 Dec 2020, 02:15 UTC

GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next execution in the loop will assign self->code_table[11].extends to c, which will give the value of 10. This will make the loop run infinitely. This bug can, for example, be triggered by calling this function with a GIF image with LZW compression that is crafted in a special way.

CVE-2020-35457 gnome vulnerability CVSS: 4.6 14 Dec 2020, 23:15 UTC

GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's position is "Realistically this is not a security issue. The standard pattern is for callers to provide a static list of option entries in a fixed number of calls to g_option_group_add_entries()." The researcher states that this pattern is undocumented

CVE-2020-16125 gnome vulnerability CVSS: 4.6 10 Nov 2020, 05:15 UTC

gdm3 versions before 3.36.2 or 3.38.2 would start gnome-initial-setup if gdm3 can't contact the accountservice service via dbus in a timely manner; on Ubuntu (and potentially derivatives) this could be be chained with an additional issue that could allow a local user to create a new privileged account.

CVE-2020-24661 gnome vulnerability CVSS: 2.6 26 Aug 2020, 16:15 UTC

GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system-provided PKCS#11 store. This allows a meddler in the middle to present a different invalid certificate to intercept incoming and outgoing mail.

CVE-2020-17489 gnome vulnerability CVSS: 1.9 11 Aug 2020, 21:15 UTC

An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment upon a logout. (If the password were never shown in cleartext, only the password length is revealed.)

CVE-2020-16118 gnome vulnerability CVSS: 5.0 29 Jul 2020, 18:15 UTC

In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c.

CVE-2020-16117 gnome vulnerability CVSS: 4.3 29 Jul 2020, 18:15 UTC

In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.

CVE-2020-14928 gnome vulnerability CVSS: 4.3 17 Jul 2020, 16:15 UTC

evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."

CVE-2020-10754 gnome vulnerability CVSS: 4.0 08 Jun 2020, 18:15 UTC

It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made insecurely.

CVE-2020-13645 gnome vulnerability CVSS: 6.4 28 May 2020, 12:15 UTC

In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications that fail to provide the server identity, including Balsa before 2.5.11 and 2.6.x before 2.6.1, accept a TLS certificate if the certificate is valid for any host.

CVE-2020-12825 gnome vulnerability CVSS: 5.8 12 May 2020, 18:15 UTC

libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.

CVE-2020-11879 gnome vulnerability CVSS: 4.3 17 Apr 2020, 18:15 UTC

An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email message without showing a warning to the user, as demonstrated by an attach=. value.

CVE-2020-11736 gnome vulnerability CVSS: 3.3 13 Apr 2020, 19:15 UTC

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

CVE-2019-20326 gnome vulnerability CVSS: 6.8 16 Mar 2020, 22:15 UTC

A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.

CVE-2012-1096 gnome vulnerability CVSS: 4.9 10 Mar 2020, 17:15 UTC

NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.

CVE-2012-0828 gnome vulnerability CVSS: 7.5 21 Feb 2020, 18:15 UTC

Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 line from server containing characters outside of the Basic Multilingual Plane (BMP).

CVE-2013-4166 gnome vulnerability CVSS: 5.0 06 Feb 2020, 15:15 UTC

The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.

CVE-2019-20446 gnome vulnerability CVSS: 4.3 02 Feb 2020, 14:15 UTC

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

CVE-2006-7246 gnome vulnerability CVSS: 3.2 27 Jan 2020, 15:15 UTC

NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.

CVE-2020-6750 gnome vulnerability CVSS: 4.3 09 Jan 2020, 20:15 UTC

GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.

CVE-2012-2736 gnome vulnerability CVSS: 3.3 26 Dec 2019, 20:15 UTC

In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.

CVE-2012-6111 gnome vulnerability CVSS: 5.0 20 Dec 2019, 15:15 UTC

gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function

CVE-2013-4245 gnome vulnerability CVSS: 4.4 11 Dec 2019, 14:15 UTC

Orca has arbitrary code execution due to insecure Python module load

CVE-2019-19308 gnome vulnerability CVSS: 4.3 27 Nov 2019, 15:15 UTC

In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing a TTF font file that lacks a name section (due to a g_strconcat call that returns NULL).

CVE-2011-3355 gnome vulnerability CVSS: 4.3 25 Nov 2019, 23:15 UTC

evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could use this flaw to obtain login credentials of the victim.

CVE-2012-5535 gnome vulnerability CVSS: 5.0 25 Nov 2019, 14:15 UTC

gnome-system-log polkit policy allows arbitrary files on the system to be read

CVE-2011-2897 gnome vulnerability CVSS: 7.5 12 Nov 2019, 14:15 UTC

gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw

CVE-2016-1000002 gnome vulnerability CVSS: 2.1 05 Nov 2019, 14:15 UTC

gdm3 3.14.2 and possibly later has an information leak before screen lock

CVE-2013-3718 gnome vulnerability CVSS: 4.3 01 Nov 2019, 13:15 UTC

evince is missing a check on number of pages which can lead to a segmentation fault

CVE-2019-17266 gnome vulnerability CVSS: 7.5 06 Oct 2019, 22:15 UTC

libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.

CVE-2019-16680 gnome vulnerability CVSS: 2.6 21 Sep 2019, 21:15 UTC

An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.

CVE-2019-3890 gnome vulnerability CVSS: 5.8 01 Aug 2019, 14:15 UTC

It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference.

CVE-2019-1010238 gnome vulnerability CVSS: 7.5 19 Jul 2019, 17:15 UTC

Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass invalid utf-8 strings to functions like pango_itemize.

CVE-2019-1010006 gnome vulnerability CVSS: 6.8 15 Jul 2019, 02:15 UTC

Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs because of an incorrect integer overflow protection mechanism in tiff_document_render and tiff_document_get_thumbnail.

CVE-2019-13012 gnome vulnerability CVSS: 5.0 28 Jun 2019, 15:15 UTC

The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and files using g_file_replace_contents (kfsb->file, contents, length, NULL, FALSE, G_FILE_CREATE_REPLACE_DESTINATION, NULL, NULL, NULL). Consequently, it does not properly restrict directory (and file) permissions. Instead, for directories, 0777 permissions are used; for files, default file permissions are used. This is similar to CVE-2019-12450.

CVE-2019-12795 gnome vulnerability CVSS: 4.6 11 Jun 2019, 22:29 UTC

daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.)

CVE-2019-12450 gnome vulnerability CVSS: 7.5 29 May 2019, 17:29 UTC

file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.

CVE-2019-12449 gnome vulnerability CVSS: 3.5 29 May 2019, 17:29 UTC

An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with G_FILE_COPY_ALL_METADATA) operations from admin:// to file:// URIs, because root privileges are unavailable.

CVE-2019-12448 gnome vulnerability CVSS: 6.8 29 May 2019, 17:29 UTC

An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c has race conditions because the admin backend doesn't implement query_info_on_read/write.

CVE-2019-12447 gnome vulnerability CVSS: 4.9 29 May 2019, 17:29 UTC

An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used.

CVE-2019-11460 gnome vulnerability CVSS: 6.8 22 Apr 2019, 22:29 UTC

An issue was discovered in GNOME gnome-desktop 3.26, 3.28, and 3.30 prior to 3.30.2.2, and 3.32 prior to 3.32.1.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal, allowing an attacker to escape the sandbox if the thumbnailer has a controlling terminal. This is due to improper filtering of the TIOCSTI ioctl on 64-bit systems, similar to CVE-2019-10063.

CVE-2019-11459 gnome vulnerability CVSS: 4.3 22 Apr 2019, 22:29 UTC

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.

CVE-2019-11461 gnome vulnerability CVSS: 4.4 22 Apr 2019, 21:29 UTC

An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal, allowing an attacker to escape the sandbox if the thumbnailer has a controlling terminal. This is due to improper filtering of the TIOCSTI ioctl on 64-bit systems, similar to CVE-2019-10063.

CVE-2019-3827 gnome vulnerability CVSS: 3.3 25 Mar 2019, 18:29 UTC

An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users belonging to the wheel group to further escalate its privileges by modifying system files without user's knowledge. Successful exploitation requires uncommon system configuration.

CVE-2019-9633 gnome vulnerability CVSS: 4.3 08 Mar 2019, 08:29 UTC

gio/gsocketclient.c in GNOME GLib 2.59.2 does not ensure that a parent GTask remains alive during the execution of a connection-attempting enumeration, which allows remote attackers to cause a denial of service (g_socket_client_connected_callback mishandling and application crash) via a crafted web site, as demonstrated by GNOME Web (aka Epiphany).

CVE-2017-12447 gnome vulnerability CVSS: 6.8 07 Mar 2019, 23:29 UTC

GdkPixBuf (aka gdk-pixbuf), possibly 2.32.2, as used by GNOME Nautilus 3.14.3 on Ubuntu 16.04, allows attackers to cause a denial of service (stack corruption) or possibly have unspecified other impact via a crafted file folder.

CVE-2018-20781 gnome vulnerability CVSS: 2.1 12 Feb 2019, 17:29 UTC

In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.

CVE-2018-15587 gnome vulnerability CVSS: 4.3 11 Feb 2019, 17:29 UTC

GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment.

CVE-2019-3825 gnome vulnerability CVSS: 6.9 06 Feb 2019, 20:29 UTC

A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by selecting the timed login user and waiting for the timer to expire, at which time they would gain access to the logged-in user's session.

CVE-2019-3820 gnome vulnerability CVSS: 4.6 06 Feb 2019, 20:29 UTC

It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.

CVE-2019-6251 gnome vulnerability CVSS: 5.8 14 Jan 2019, 08:29 UTC

WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.

CVE-2018-19358 gnome vulnerability CVSS: 2.1 18 Nov 2018, 19:29 UTC

GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that this occurs because available D-Bus protection mechanisms (involving the busconfig and policy XML elements) are not used. NOTE: the vendor disputes this because, according to the security model, untrusted applications must not be allowed to access the user's session bus socket.

CVE-2008-7320 gnome vulnerability CVSS: 2.1 18 Nov 2018, 19:29 UTC

GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow dialog at an unattended workstation, if the keyring is unlocked. NOTE: this is disputed by a software maintainer because the behavior represents a design decision

CVE-2018-18718 gnome vulnerability CVSS: 4.6 29 Oct 2018, 12:29 UTC

An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the add_themes_from_dir method in dlg-contact-sheet.c because of two successive calls of g_free, each of which frees the same buffer.

CVE-2018-16429 gnome vulnerability CVSS: 5.0 04 Sep 2018, 00:29 UTC

GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().

CVE-2018-16428 gnome vulnerability CVSS: 7.5 04 Sep 2018, 00:29 UTC

In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.

CVE-2018-15120 gnome vulnerability CVSS: 4.3 24 Aug 2018, 19:29 UTC

libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.

CVE-2018-14424 gnome vulnerability CVSS: 4.6 14 Aug 2018, 18:29 UTC

The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code execution.

CVE-2017-12164 gnome vulnerability CVSS: 6.9 26 Jul 2018, 16:29 UTC

A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as another user' to unlock their screen.

CVE-2018-10900 gnome vulnerability CVSS: 7.2 26 Jul 2018, 15:29 UTC

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.

CVE-2016-10727 gnome vulnerability CVSS: 5.0 20 Jul 2018, 04:29 UTC

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.

CVE-2018-12910 gnome vulnerability CVSS: 7.5 05 Jul 2018, 18:29 UTC

The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.

CVE-2018-12422 gnome vulnerability CVSS: 7.5 15 Jun 2018, 16:29 UTC

addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that is processed by the strcat function. NOTE: the software maintainer disputes this because "the code had computed the required string length first, and then allocated a large-enough buffer on the heap.

CVE-2018-12016 gnome vulnerability CVSS: 5.0 07 Jun 2018, 14:29 UTC

libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via certain window.open and document.write calls.

CVE-2018-11713 gnome vulnerability CVSS: 4.3 04 Jun 2018, 14:29 UTC

WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy settings for WebSocket connections. As a result, users could be deanonymized by crafted web sites via a WebSocket connection.

CVE-2018-11396 gnome vulnerability CVSS: 5.0 23 May 2018, 13:29 UTC

ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrated by a crafted window.open call.

CVE-2017-17689 gnome vulnerability CVSS: 4.3 16 May 2018, 19:29 UTC

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVE-2018-10767 gnome vulnerability CVSS: 4.3 06 May 2018, 23:29 UTC

There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack.

CVE-2018-10733 gnome vulnerability CVSS: 4.3 04 May 2018, 17:29 UTC

There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.

CVE-2017-2885 gnome vulnerability CVSS: 7.5 24 Apr 2018, 19:29 UTC

An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow resulting in remote code execution. An attacker can send a special HTTP request to the vulnerable server to trigger this vulnerability.

CVE-2018-1000135 gnome vulnerability CVSS: 5.0 20 Mar 2018, 13:29 UTC

GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DNS queries leaked to local network's DNS servers, while on VPN. This vulnerability appears to have been fixed in Some Ubuntu 16.04 packages were fixed, but later updates removed the fix. cf. https://bugs.launchpad.net/ubuntu/+bug/1754671 an upstream fix does not appear to be available at this time.

CVE-2018-1000041 gnome vulnerability CVSS: 4.3 09 Feb 2018, 23:29 UTC

GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can result in the victim's Windows username and NTLM password hash being leaked to remote attackers through SMB. This attack appear to be exploitable via The victim must process a specially crafted SVG file containing an UNC path on Windows.

CVE-2018-5345 gnome vulnerability CVSS: 6.8 12 Jan 2018, 00:29 UTC

A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file.

CVE-2017-1000422 gnome vulnerability CVSS: 6.8 02 Jan 2018, 20:29 UTC

Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential code execution

CVE-2017-1000159 gnome vulnerability CVSS: 4.6 27 Nov 2017, 15:29 UTC

Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.

CVE-2017-14604 gnome vulnerability CVSS: 4.0 20 Sep 2017, 08:29 UTC

GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .desktop file's Name field ends in .pdf but this file's Exec field launches a malicious "sh -c" command. In other words, Nautilus provides no UI indication that a file actually has the potentially unsafe .desktop extension; instead, the UI only shows the .pdf extension. One (slightly) mitigating factor is that an attack requires the .desktop file to have execute permission. The solution is to ask the user to confirm that the file is supposed to be treated as a .desktop file, and then remember the user's answer in the metadata::trusted field.

CVE-2017-2870 gnome vulnerability CVSS: 6.8 05 Sep 2017, 18:29 UTC

An exploitable integer overflow vulnerability exists in the tiff_image_parse functionality of Gdk-Pixbuf 2.36.6 when compiled with Clang. A specially crafted tiff file can cause a heap-overflow resulting in remote code execution. An attacker can send a file or a URL to trigger this vulnerability.

CVE-2017-2862 gnome vulnerability CVSS: 6.8 05 Sep 2017, 18:29 UTC

An exploitable heap overflow vulnerability exists in the gdk_pixbuf__jpeg_image_load_increment functionality of Gdk-Pixbuf 2.36.6. A specially crafted jpeg file can cause a heap overflow resulting in remote code execution. An attacker can send a file or url to trigger this vulnerability.

CVE-2017-14108 gnome vulnerability CVSS: 7.1 05 Sep 2017, 06:29 UTC

libgedit.a in GNOME gedit through 3.22.1 allows remote attackers to cause a denial of service (CPU consumption) via a file that begins with many '\0' characters.

CVE-2017-1000083 gnome vulnerability CVSS: 6.8 05 Sep 2017, 06:29 UTC

backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.

CVE-2015-2675 gnome vulnerability CVSS: 5.0 18 Aug 2017, 18:29 UTC

The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (application crash) via running the EnsureCredentials method from the org.gnome.OnlineAccounts.Account interface on an object representing a Flickr account.

CVE-2017-11590 gnome vulnerability CVSS: 4.3 24 Jul 2017, 01:29 UTC

There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.

CVE-2017-11464 gnome vulnerability CVSS: 6.8 19 Jul 2017, 21:29 UTC

A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because of incorrect protection against division by zero.

CVE-2017-1000044 gnome vulnerability CVSS: 7.5 17 Jul 2017, 13:18 UTC

gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when rendering

CVE-2017-1000025 gnome vulnerability CVSS: 5.0 17 Jul 2017, 13:18 UTC

GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfiltration of stored passwords for a selected set of websites.

CVE-2017-1000024 gnome vulnerability CVSS: 5.0 17 Jul 2017, 13:18 UTC

Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext transmission

CVE-2017-11171 gnome vulnerability CVSS: 4.9 11 Jul 2017, 20:29 UTC

Bad reference counting in the context of accept_ice_connection() in gsm-xsmp-server.c in old versions of gnome-session up until version 2.29.92 allows a local attacker to establish ICE connections to gnome-session with invalid authentication data (an invalid magic cookie). Each failed authentication attempt will leak a file descriptor in gnome-session. When the maximum number of file descriptors is exhausted in the gnome-session process, it will enter an infinite loop trying to communicate without success, consuming 100% of the CPU. The graphical session associated with the gnome-session process will stop working correctly, because communication with gnome-session is no longer possible.

CVE-2017-8871 gnome vulnerability CVSS: 7.1 12 Jun 2017, 06:29 UTC

The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file.

CVE-2017-8834 gnome vulnerability CVSS: 4.3 12 Jun 2017, 06:29 UTC

The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (memory allocation error) via a crafted CSS file.

CVE-2017-8288 gnome vulnerability CVSS: 6.8 27 Apr 2017, 00:59 UTC

gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what music you were playing), or even execute arbitrary commands. It all depends on what extensions a user has enabled. The problem is caused by lack of exception handling in js/ui/extensionSystem.js.

CVE-2017-7961 gnome vulnerability CVSS: 6.8 19 Apr 2017, 15:59 UTC

The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable values of type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CSS file. NOTE: third-party analysis reports "This is not a security issue in my view. The conversion surely is truncating the double into a long value, but there is no impact as the value is one of the RGB components.

CVE-2017-7960 gnome vulnerability CVSS: 4.3 19 Apr 2017, 15:59 UTC

The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.

CVE-2017-6314 gnome vulnerability CVSS: 4.3 10 Mar 2017, 02:59 UTC

The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (infinite loop) via a large TIFF file.

CVE-2017-6313 gnome vulnerability CVSS: 5.8 10 Mar 2017, 02:59 UTC

Integer underflow in the load_resources function in io-icns.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (out-of-bounds read and program crash) via a crafted image entry size in an ICO file.

CVE-2017-6312 gnome vulnerability CVSS: 4.3 10 Mar 2017, 02:59 UTC

Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, which triggers an out-of-bounds read, related to compiler optimizations.

CVE-2017-6311 gnome vulnerability CVSS: 5.0 10 Mar 2017, 02:59 UTC

gdk-pixbuf-thumbnailer.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to printing an error message.

CVE-2017-5885 gnome vulnerability CVSS: 7.5 28 Feb 2017, 18:59 UTC

Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.

CVE-2017-5884 gnome vulnerability CVSS: 6.8 28 Feb 2017, 18:59 UTC

gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.

CVE-2016-6163 gnome vulnerability CVSS: 4.3 03 Feb 2017, 15:59 UTC

The rsvg_pattern_fix_fallback function in rsvg-paint_server.c in librsvg2 2.40.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted svg file.

CVE-2016-9888 gnome vulnerability CVSS: 4.3 08 Dec 2016, 08:59 UTC

An error within the "tar_directory_for_file()" function (gsf-infile-tar.c) in GNOME Structured File Library before 1.14.41 can be exploited to trigger a Null pointer dereference and subsequently cause a crash via a crafted TAR file.

CVE-2016-1000033 gnome vulnerability CVSS: 4.3 25 Oct 2016, 14:29 UTC

Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.

CVE-2016-6352 gnome vulnerability CVSS: 5.0 03 Oct 2016, 18:59 UTC

The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via crafted dimensions in an ICO file.

CVE-2016-6855 gnome vulnerability CVSS: 5.0 07 Sep 2016, 18:59 UTC

Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.

CVE-2015-8875 gnome vulnerability CVSS: 6.8 01 Jun 2016, 22:59 UTC

Multiple integer overflows in the (1) pixops_composite_nearest, (2) pixops_composite_color_nearest, and (3) pixops_process functions in pixops/pixops.c in gdk-pixbuf before 2.33.1 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image, which triggers a heap-based buffer overflow.

CVE-2016-4348 gnome vulnerability CVSS: 5.0 20 May 2016, 14:59 UTC

The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via circular definitions in an SVG document.

CVE-2015-7558 gnome vulnerability CVSS: 5.0 20 May 2016, 14:59 UTC

librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via cyclic references in an SVG document.

CVE-2015-7557 gnome vulnerability CVSS: 5.0 20 May 2016, 14:59 UTC

The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via an odd number of elements in a coordinate pair in an SVG document.

CVE-2015-7496 gnome vulnerability CVSS: 7.2 24 Nov 2015, 20:59 UTC

GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the Escape key.

CVE-2015-0272 gnome vulnerability CVSS: 5.0 17 Nov 2015, 15:59 UTC

GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message, a different vulnerability than CVE-2015-8215.

CVE-2015-7674 gnome vulnerability CVSS: 6.8 26 Oct 2015, 17:59 UTC

Integer overflow in the pixops_scale_nearest function in pixops/pixops.c in gdk-pixbuf before 2.32.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted GIF image file, which triggers a heap-based buffer overflow.

CVE-2015-7673 gnome vulnerability CVSS: 6.8 26 Oct 2015, 17:59 UTC

io-tga.c in gdk-pixbuf before 2.32.0 uses heap memory after its allocation failed, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) and possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file.

CVE-2015-4491 gnome vulnerability CVSS: 6.8 16 Aug 2015, 01:59 UTC

Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via crafted bitmap dimensions that are mishandled during scaling.

CVE-2015-2785 gnome vulnerability CVSS: 7.5 29 Mar 2015, 21:59 UTC

The GIF encoder in Byzanz allows remote attackers to cause a denial of service (out-of-bounds heap write and crash) or possibly execute arbitrary code via a crafted Byzanz debug data recording (ByzanzRecording file) to the byzanz-playback command.

CVE-2014-8154 gnome vulnerability CVSS: 7.5 27 Jan 2015, 20:59 UTC

The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which trigger a heap-based buffer overflow.

CVE-2014-1949 gnome vulnerability CVSS: 7.2 16 Jan 2015, 16:59 UTC

GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.

CVE-2015-0552 gnome vulnerability CVSS: 6.4 15 Jan 2015, 15:59 UTC

Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder.c in gcab 0.4 allows remote attackers to write to arbitrary files via crafted path in a CAB file, as demonstrated by "\tmp\moo."

CVE-2014-7300 gnome vulnerability CVSS: 7.2 25 Dec 2014, 21:59 UTC

GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a temporary lock outage, and the resulting temporary shell availability, caused by the Linux kernel OOM killer.

CVE-2011-2198 gnome vulnerability CVSS: 3.5 21 May 2014, 14:55 UTC

The "insert-blank-characters" capability in caps.c in gnome-terminal (vte) before 0.28.1 allows remote authenticated users to cause a denial of service (CPU and memory consumption and crash) via a crafted file, as demonstrated by a file containing the string "\033[100000000000000000@".

CVE-2013-7273 gnome vulnerability CVSS: 2.1 29 Apr 2014, 14:38 UTC

GNOME Display Manager (gdm) 3.4.1 and earlier, when disable-user-list is set to true, allows local users to cause a denial of service (unable to login) by pressing the cancel button after entering a user name.

CVE-2013-7221 gnome vulnerability CVSS: 4.6 29 Apr 2014, 14:38 UTC

The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Enter a Command" dialog, which allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation.

CVE-2013-7220 gnome vulnerability CVSS: 4.6 29 Apr 2014, 14:38 UTC

js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with the keyboard focus on the Activities search.

CVE-2013-6836 gnome vulnerability CVSS: 4.3 19 Dec 2013, 04:24 UTC

Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a crafted length value.

CVE-2013-1881 gnome vulnerability CVSS: 4.3 10 Oct 2013, 00:55 UTC

GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVE-2013-4169 gnome vulnerability CVSS: 6.9 10 Sep 2013, 19:55 UTC

GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/.

CVE-2013-1799 gnome vulnerability CVSS: 4.3 02 Apr 2013, 03:23 UTC

Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network. NOTE: this issue exists because of an incomplete fix for CVE-2013-0240.

CVE-2013-0240 gnome vulnerability CVSS: 4.3 02 Apr 2013, 03:22 UTC

Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network.

CVE-2013-1050 gnome vulnerability CVSS: 7.2 08 Mar 2013, 22:55 UTC

The default configuration in gnome-screensaver 3.5.4 through 3.6.0 sets the AutostartCondition line to fallback mode in the .desktop file, which prevents the program from starting automatically after login and allows physically proximate attackers to bypass screen locking and access an unattended workstation.

CVE-2011-3201 gnome vulnerability CVSS: 4.3 08 Mar 2013, 21:55 UTC

GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.

CVE-2010-2387 gnome vulnerability CVSS: 1.9 21 Dec 2012, 05:46 UTC

vicious-extensions/ve-misc.c in GNOME Display Manager (gdm) 2.20.x before 2.20.11, when GDM debug is enabled, logs the user password when it contains invalid UTF8 encoded characters, which might allow local users to gain privileges by reading the information from syslog logs.

CVE-2011-5244 gnome vulnerability CVSS: 6.8 19 Nov 2012, 12:10 UTC

Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, different vulnerabilities than CVE-2010-2642 and CVE-2011-0433.

CVE-2011-0433 gnome vulnerability CVSS: 6.8 19 Nov 2012, 12:10 UTC

Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, a different vulnerability than CVE-2010-2642.

CVE-2012-4511 gnome vulnerability CVSS: 5.8 22 Oct 2012, 23:55 UTC

services/flickr/flickr.c in libsocialweb before 0.25.21 automatically connects to Flickr when no Flickr account is set, which might allow remote attackers to obtain sensitive information via a man-in-the-middle (MITM) attack.

CVE-2012-3466 gnome vulnerability CVSS: 4.4 22 Oct 2012, 23:55 UTC

GNOME gnome-keyring 3.4.0 through 3.4.1, when gpg-cache-method is set to "idle" or "timeout," does not properly limit the amount of time a passphrase is cached, which allows attackers to have an unspecified impact via unknown attack vectors.

CVE-2011-4129 gnome vulnerability CVSS: 5.8 22 Oct 2012, 23:55 UTC

(1) services/twitter/twitter-contact-view.c and (2) services/twitter/twitter-item-view.c in libsocialweb before 0.25.20 automatically connect to Twitter when no Twitter account is set, which might allow remote attackers to obtain sensitive information via a man-in-the-middle (MITM) attack.

CVE-2012-4427 gnome vulnerability CVSS: 6.8 01 Oct 2012, 03:26 UTC

The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a crafted web page.

CVE-2011-3146 gnome vulnerability CVSS: 6.8 05 Sep 2012, 23:55 UTC

librsvg before 2.34.1 uses the node name to identify the type of node, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference) and possibly execute arbitrary code via a SVG file with a node with the element name starting with "fe," which is misidentified as a RsvgFilterPrimitive.

CVE-2012-3378 gnome vulnerability CVSS: 3.3 31 Aug 2012, 18:55 UTC

The register_application function in atk-adaptor/bridge.c in GNOME at-spi2-atk 2.5.2 does not seed the random number generator and generates predictable temporary file names, which makes it easier for local users to create or truncate files via a symlink attack on a temporary socket file in /tmp/at-spi2.

CVE-2012-2132 gnome vulnerability CVSS: 5.0 20 Aug 2012, 18:55 UTC

libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.

CVE-2012-2370 gnome vulnerability CVSS: 5.0 13 Aug 2012, 20:55 UTC

Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in gdk-pixbuf before 2.26.1 allow remote attackers to cause a denial of service (application crash) via a negative (1) height or (2) width in an XBM file, which triggers a heap-based buffer overflow.

CVE-2012-3452 gnome vulnerability CVSS: 3.3 07 Aug 2012, 20:55 UTC

gnome-screensaver 3.4.x before 3.4.4 and 3.5.x before 3.5.4, when multiple screens are used, only locks the screen with the active focus, which allows physically proximate attackers to bypass screen locking and access an unattended workstation.

CVE-2012-3355 gnome vulnerability CVSS: 3.6 17 Jul 2012, 21:55 UTC

(1) AlbumTab.py, (2) ArtistTab.py, (3) LinksTab.py, and (4) LyricsTab.py in the Context module in GNOME Rhythmbox 0.13.3 and earlier allows local users to execute arbitrary code via a symlink attack on a temporary HTML template file in the /tmp/context directory.

CVE-2011-2485 gnome vulnerability CVSS: 4.3 03 Jul 2012, 16:40 UTC

The gdk_pixbuf__gif_image_load function in gdk-pixbuf/io-gif.c in gdk-pixbuf before 2.23.5 does not properly handle certain return values, which allows remote attackers to cause a denial of service (memory consumption) via a crafted GIF image file.

CVE-2011-3193 gnome vulnerability CVSS: 9.3 16 Jun 2012, 00:55 UTC

Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.

CVE-2012-0948 gnome vulnerability CVSS: 2.1 07 Jun 2012, 21:55 UTC

DistUpgrade/DistUpgradeMain.py in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uses weak permissions for (1) apt-clone_system_state.tar.gz and (2) system_state.tar.gz, which allows local users to obtain repository credentials.

CVE-2012-0039 gnome vulnerability CVSS: 5.0 14 Jan 2012, 17:55 UTC

GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.

CVE-2011-3364 gnome vulnerability CVSS: 6.9 04 Nov 2011, 21:55 UTC

Incomplete blacklist vulnerability in the svEscape function in settings/plugins/ifcfg-rh/shvar.c in the ifcfg-rh plug-in for GNOME NetworkManager 0.9.1, 0.9.0, 0.8.1, and possibly other versions, when PolicyKit is configured to allow users to create new connections, allows local users to execute arbitrary commands via a newline character in the name for a new network connection, which is not properly handled when writing to the ifcfg file.

CVE-2011-4170 gnome vulnerability CVSS: 4.3 23 Oct 2011, 10:55 UTC

Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted alias (aka nickname) in a /me event, a different vulnerability than CVE-2011-3635.

CVE-2011-3635 gnome vulnerability CVSS: 4.3 23 Oct 2011, 10:55 UTC

Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted alias (aka nickname).

CVE-2010-4833 gnome vulnerability CVSS: 9.3 06 Sep 2011, 15:55 UTC

Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan horse uxtheme.dll file in the current working directory, a different vulnerability than CVE-2010-4831.

CVE-2010-4831 gnome vulnerability CVSS: 6.9 06 Sep 2011, 15:55 UTC

Untrusted search path vulnerability in gdk/win32/gdkinput-win32.c in GTK+ before 2.21.8 allows local users to gain privileges via a Trojan horse Wintab32.dll file in the current working directory.

CVE-2011-2176 gnome vulnerability CVSS: 2.1 02 Sep 2011, 23:55 UTC

GNOME NetworkManager before 0.8.6 does not properly enforce the auth_admin element in PolicyKit, which allows local users to bypass intended wireless network sharing restrictions via unspecified vectors.

CVE-2011-2524 gnome vulnerability CVSS: 5.0 31 Aug 2011, 23:55 UTC

Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI.

CVE-2011-1943 gnome vulnerability CVSS: 2.1 14 Jun 2011, 17:55 UTC

The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0.8.999-3.git20110526 in Fedora 15 creates a log entry containing a certificate password, which allows local users to obtain sensitive information by reading a log file.

CVE-2011-1709 gnome vulnerability CVSS: 7.2 14 Jun 2011, 17:55 UTC

GNOME Display Manager (gdm) before 2.32.2, when glib 2.28 is used, enables execution of a web browser with the uid of the gdm account, which allows local users to gain privileges via vectors involving the x-scheme-handler/http MIME type.

CVE-2011-0727 gnome vulnerability CVSS: 6.9 31 Mar 2011, 22:55 UTC

GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/.

CVE-2011-0064 gnome vulnerability CVSS: 6.8 07 Mar 2011, 21:00 UTC

The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via crafted OpenType font data that triggers use of an incorrect index.

CVE-2011-0020 gnome vulnerability CVSS: 7.6 24 Jan 2011, 18:00 UTC

Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file, related to the glyph box for an FT_Bitmap object.

CVE-2010-4005 gnome vulnerability CVSS: 6.9 06 Nov 2010, 00:00 UTC

The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: vector 1 exists because of an incorrect fix for CVE-2005-4790.2.

CVE-2010-4000 gnome vulnerability CVSS: 6.9 06 Nov 2010, 00:00 UTC

gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

CVE-2010-3312 gnome vulnerability CVSS: 5.8 14 Oct 2010, 05:58 UTC

Epiphany 2.28 and 2.29, when WebKit and LibSoup are used, unconditionally displays a closed-lock icon for any URL beginning with the https: substring, without any warning to the user, which allows man-in-the-middle attackers to spoof arbitrary https web sites via a crafted X.509 server certificate.

CVE-2009-4997 gnome vulnerability CVSS: 7.2 07 Sep 2010, 18:00 UTC

gnome-power-manager 2.27.92 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to CVE-2010-2532. NOTE: this issue exists because of a regression that followed a gnome-power-manager fix a few years earlier.

CVE-2006-7240 gnome vulnerability CVSS: 7.2 07 Sep 2010, 18:00 UTC

gnome-power-manager 2.14.0 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to CVE-2010-2532.

CVE-2010-0732 gnome vulnerability CVSS: 6.2 19 Mar 2010, 19:30 UTC

gdk/gdkwindow.c in GTK+ before 2.18.5, as used in gnome-screensaver before 2.28.1, performs implicit paints on windows of type GDK_WINDOW_FOREIGN, which triggers an X error in certain circumstances and consequently allows physically proximate attackers to bypass screen locking and access an unattended workstation by pressing the Enter key many times.

CVE-2010-0421 gnome vulnerability CVSS: 4.3 18 Mar 2010, 17:30 UTC

Array index error in the hb_ot_layout_build_glyph_classes function in pango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted font file, related to building a synthetic Glyph Definition (aka GDEF) table by using this font's charmap and the Unicode property database.

CVE-2010-0422 gnome vulnerability CVSS: 4.0 24 Feb 2010, 18:30 UTC

gnome-screensaver 2.28.x before 2.28.3 does not properly synchronize the state of screen locking and the unlock dialog in situations involving a change to the number of monitors, which allows physically proximate attackers to bypass screen locking and access an unattended workstation by connecting and disconnecting monitors multiple times, a related issue to CVE-2010-0414.

CVE-2010-0285 gnome vulnerability CVSS: 5.6 24 Feb 2010, 18:30 UTC

gnome-screensaver 2.14.3, 2.22.2, 2.27.x, 2.28.0, and 2.28.3, when the X configuration enables the extend screen option, allows physically proximate attackers to bypass screen locking, access an unattended workstation, and view half of the GNOME desktop by attaching an external monitor.

CVE-2009-4642 gnome vulnerability CVSS: 7.2 11 Feb 2010, 21:30 UTC

gnome-screensaver 2.26.1 relies on the gnome-session D-Bus interface to determine session idle time, even when an Xfce desktop such as Xubuntu or Mythbuntu is used, which allows physically proximate attackers to access an unattended workstation on which screen locking had been intended.

CVE-2009-4641 gnome vulnerability CVSS: 7.2 11 Feb 2010, 21:30 UTC

gnome-screensaver 2.28.0 does not resume adherence to its activation settings after an inhibiting application becomes unavailable on the session bus, which allows physically proximate attackers to access an unattended workstation on which screen locking had been intended.

CVE-2010-0414 gnome vulnerability CVSS: 7.2 11 Feb 2010, 20:30 UTC

gnome-screensaver before 2.28.2 allows physically proximate attackers to bypass screen locking and access an unattended workstation by moving the mouse position to an external monitor and then disconnecting that monitor.

CVE-2010-0409 gnome vulnerability CVSS: 7.5 08 Feb 2010, 21:30 UTC

Buffer overflow in the GMIME_UUENCODE_LEN macro in gmime/gmime-encodings.h in GMime before 2.4.15 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via input data for a uuencode operation.

CVE-2009-4145 gnome vulnerability CVSS: 2.1 23 Dec 2009, 20:30 UTC

nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to discover the password for the WiFi network.

CVE-2009-4144 gnome vulnerability CVSS: 6.8 23 Dec 2009, 20:30 UTC

NetworkManager (NM) 0.7.2 does not ensure that the configured Certification Authority (CA) certificate file for a (1) WPA Enterprise or (2) 802.1x network remains present upon a connection attempt, which might allow remote attackers to obtain sensitive information or cause a denial of service (connectivity disruption) by spoofing the identity of a wireless network.

CVE-2009-4035 gnome vulnerability CVSS: 9.3 21 Dec 2009, 21:30 UTC

The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.

CVE-2009-3289 gnome vulnerability CVSS: 4.4 22 Sep 2009, 10:30 UTC

The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.

CVE-2008-7185 gnome vulnerability CVSS: 4.3 08 Sep 2009, 23:30 UTC

GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlist (.pls) file with a long Title field, possibly related to the g_hash_table_lookup function in b-playlist-manager.c.

CVE-2009-2697 gnome vulnerability CVSS: 6.8 04 Sep 2009, 20:30 UTC

The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions via XDMCP connections, a different vulnerability than CVE-2007-5079.

CVE-2009-1631 gnome vulnerability CVSS: 2.1 14 May 2009, 17:30 UTC

The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to local mail, which allows local users to obtain sensitive information by reading these files.

CVE-2009-0582 gnome vulnerability CVSS: 5.8 14 Mar 2009, 18:30 UTC

The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier, and 2.25.92 and earlier 2.25.x versions, does not validate whether a certain length value is consistent with the amount of data in a challenge packet, which allows remote mail servers to read information from the process memory of a client, or cause a denial of service (client crash), via an NTLM authentication type 2 packet with a length value that exceeds the amount of packet data.

CVE-2008-4316 gnome vulnerability CVSS: 4.6 14 Mar 2009, 18:30 UTC

Multiple integer overflows in glib/gbase64.c in GLib before 2.20 allow context-dependent attackers to execute arbitrary code via a long string that is converted either (1) from or (2) to a base64 representation.

CVE-2009-0318 gnome vulnerability CVSS: 6.9 28 Jan 2009, 11:30 UTC

Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

CVE-2009-0317 gnome vulnerability CVSS: 6.9 28 Jan 2009, 11:30 UTC

Untrusted search path vulnerability in the Python language bindings for Nautilus (nautilus-python) allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

CVE-2009-0314 gnome vulnerability CVSS: 6.9 28 Jan 2009, 11:30 UTC

Untrusted search path vulnerability in the Python module in gedit allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

CVE-2008-5987 gnome vulnerability CVSS: 6.9 28 Jan 2009, 11:30 UTC

Untrusted search path vulnerability in the Python interface in Eye of GNOME (eog) 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

CVE-2008-5985 gnome vulnerability CVSS: 6.9 28 Jan 2009, 11:30 UTC

Untrusted search path vulnerability in the Python interface in Epiphany 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

CVE-2008-5660 gnome vulnerability CVSS: 6.8 17 Dec 2008, 20:30 UTC

Format string vulnerability in the vinagre_utils_show_error function (src/vinagre-utils.c) in Vinagre 0.5.x before 0.5.2 and 2.x before 2.24.2 might allow remote attackers to execute arbitrary code via format string specifiers in a crafted URI or VNC server response.

CVE-2008-3533 gnome vulnerability CVSS: 10.0 18 Aug 2008, 17:41 UTC

Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to execute arbitrary code via format string specifiers in an invalid URI on the command line, as demonstrated by use of yelp within (1) man or (2) ghelp URI handlers in Firefox, Evolution, and unspecified other programs.

CVE-2008-1109 gnome vulnerability CVSS: 9.3 04 Jun 2008, 20:32 UTC

Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar attachment, which is not properly handled during a reply in the calendar view (aka the Calendars window).

CVE-2008-1108 gnome vulnerability CVSS: 7.6 04 Jun 2008, 20:32 UTC

Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attachment.

CVE-2008-0072 gnome vulnerability CVSS: 6.8 06 Mar 2008, 00:44 UTC

Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to execute arbitrary code via a crafted encrypted message, as demonstrated using the Version field.

CVE-2007-6389 gnome vulnerability CVSS: 2.1 17 Dec 2007, 18:46 UTC

The notify feature in GNOME screensaver (gnome-screensaver) 2.20.0 might allow local users to read the clipboard contents and X selection data for a locked session by using ctrl-V.

CVE-2007-5007 gnome vulnerability CVSS: 6.8 12 Dec 2007, 22:10 UTC

Stack-based buffer overflow in the ir_fetch_seq function in balsa before 2.3.20 might allow remote IMAP servers to execute arbitrary code via a long response to a FETCH command.

CVE-2007-3920 gnome vulnerability CVSS: 6.2 29 Oct 2007, 21:46 UTC

GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069.

CVE-2007-5337 gnome vulnerability CVSS: 4.3 21 Oct 2007, 20:17 UTC

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other files from the server.

CVE-2007-3381 gnome vulnerability CVSS: 1.5 07 Aug 2007, 10:17 UTC

The GDM daemon in GNOME Display Manager (GDM) before 2.14.13, 2.16.x before 2.16.7, 2.18.x before 2.18.4, and 2.19.x before 2.19.5 does not properly handle NULL return values from the g_strsplit function, which allows local users to cause a denial of service (persistent daemon crash) via a crafted command to the daemon's socket, related to (1) gdm.c and (2) gdmconfig.c in daemon/, and (3) gdmconfig.c and (4) gdmflexiserver.c in gui/.

CVE-2007-3257 gnome vulnerability CVSS: 6.8 19 Jun 2007, 16:30 UTC

Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index.

CVE-2007-1266 gnome vulnerability CVSS: 5.0 06 Mar 2007, 20:19 UTC

Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.

CVE-2007-0010 gnome vulnerability CVSS: 2.1 24 Jan 2007, 19:28 UTC

The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image file.

CVE-2006-6698 gnome vulnerability CVSS: 1.9 22 Dec 2006, 18:28 UTC

The GConf daemon (gconfd) in GConf 2.14.0 creates temporary files under directories with names based on the username, even when GCONF_GLOBAL_LOCKS is not set, which allows local users to cause a denial of service by creating the directories ahead of time, which prevents other users from using Gnome.

CVE-2006-6105 gnome vulnerability CVSS: 4.3 15 Dec 2006, 02:28 UTC

Format string vulnerability in the host chooser window (gdmchooser) in GNOME Foundation Display Manager (gdm) allows local users to execute arbitrary code via format string specifiers in a hostname, which are used in an error dialog.

CVE-2006-3057 gnome vulnerability CVSS: 5.0 16 Jun 2006, 10:02 UTC

Unspecified vulnerability in NetworkManager daemon for DHCP (dhcdbd) allows remote attackers to cause a denial of service (crash) via certain invalid DHCP responses that trigger memory corruption.

CVE-2006-2452 gnome vulnerability CVSS: 3.7 09 Jun 2006, 10:02 UTC

GNOME GDM 2.8, 2.12, 2.14, and 2.15, when the "face browser" feature is enabled, allows local users to access the "Configure Login Manager" functionality using their own password instead of the root password, which can be leveraged to gain additional privileges.

CVE-2006-2789 gnome vulnerability CVSS: 2.6 02 Jun 2006, 22:02 UTC

Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when "load images if sender in addressbook" is enabled, allows remote attackers to cause a denial of service (persistent crash) via a crafted "From" header that triggers an assert error in camel-internet-address.c when a null pointer is used.

CVE-2006-1057 gnome vulnerability CVSS: 3.7 25 Apr 2006, 01:02 UTC

Race condition in daemon/slave.c in gdm before 2.14.1 allows local users to gain privileges via a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file.

CVE-2006-1244 gnome vulnerability CVSS: 7.6 15 Mar 2006, 19:06 UTC

Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc. NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed. Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.

CVE-2006-0819 gnome vulnerability CVSS: 7.8 13 Mar 2006, 19:34 UTC

Dwarf HTTP Server 1.3.2 allows remote attackers to obtain the source code of JSP files via (1) dot, (2) space, (3) slash, or (4) NULL characters in the filename extension of an HTTP request.

CVE-2006-0820 gnome vulnerability CVSS: 4.3 13 Mar 2006, 19:34 UTC

Cross-site scripting (XSS) vulnerability in Dwarf HTTP Server 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified error messages.

CVE-2006-0040 gnome vulnerability CVSS: 5.0 10 Mar 2006, 01:02 UTC

GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml.

CVE-2006-0528 gnome vulnerability CVSS: 5.0 02 Feb 2006, 11:02 UTC

The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to repeatedly crash until the e-mail message is manually removed, possibly due to a buffer overflow, as demonstrated using an XML attachment.

CVE-2005-2975 gnome vulnerability CVSS: 7.8 18 Nov 2005, 06:03 UTC

io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.

CVE-2005-2976 gnome vulnerability CVSS: 7.5 18 Nov 2005, 06:03 UTC

Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a different vulnerability than CVE-2005-3186.

CVE-2005-3186 gnome vulnerability CVSS: 7.5 18 Nov 2005, 06:03 UTC

Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which leads to a heap-based buffer overflow.

CVE-2005-0023 gnome vulnerability CVSS: 2.1 05 Oct 2005, 21:02 UTC

gnome-pty-helper in GNOME libzvt2 and libvte4 allows local users to spoof the logon hostname via a modified DISPLAY environment variable. NOTE: the severity of this issue has been disputed.

CVE-2005-2549 gnome vulnerability CVSS: 7.5 12 Aug 2005, 04:00 UTC

Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.

CVE-2005-2550 gnome vulnerability CVSS: 7.5 12 Aug 2005, 04:00 UTC

Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab.

CVE-2005-2410 gnome vulnerability CVSS: 7.5 01 Aug 2005, 04:00 UTC

Format string vulnerability in the nm_info_handler function in Network Manager may allow remote attackers to execute arbitrary code via format string specifiers in a Wireless Access Point identifier, which is not properly handled in a syslog call.

CVE-2005-1686 gnome vulnerability CVSS: 2.6 20 May 2005, 04:00 UTC

Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename. NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.

CVE-2005-0238 gnome vulnerability CVSS: 5.0 02 May 2005, 04:00 UTC

The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.

CVE-2005-0372 gnome vulnerability CVSS: 5.0 02 May 2005, 04:00 UTC

Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.

CVE-2005-0891 gnome vulnerability CVSS: 5.0 02 May 2005, 04:00 UTC

Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.

CVE-2005-0206 gnome vulnerability CVSS: 7.5 27 Apr 2005, 04:00 UTC

The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.

CVE-2004-0888 gnome vulnerability CVSS: 10.0 27 Jan 2005, 05:00 UTC

Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.

CVE-2004-0889 gnome vulnerability CVSS: 10.0 27 Jan 2005, 05:00 UTC

Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.

CVE-2005-0102 gnome vulnerability CVSS: 7.2 24 Jan 2005, 05:00 UTC

Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.

CVE-2004-0782 gnome vulnerability CVSS: 7.5 20 Oct 2004, 04:00 UTC

Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).

CVE-2004-0783 gnome vulnerability CVSS: 7.5 20 Oct 2004, 04:00 UTC

Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).

CVE-2004-0753 gnome vulnerability CVSS: 5.0 20 Oct 2004, 04:00 UTC

The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted BMP file.

CVE-2004-0788 gnome vulnerability CVSS: 5.0 20 Oct 2004, 04:00 UTC

Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted ICO file.

CVE-2004-0111 gnome vulnerability CVSS: 5.0 15 Apr 2004, 04:00 UTC

gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.

CVE-2003-0793 gnome vulnerability CVSS: 2.1 17 Nov 2003, 05:00 UTC

GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not restrict the size of input, which allows attackers to cause a denial of service (memory consumption).

CVE-2003-0794 gnome vulnerability CVSS: 2.1 17 Nov 2003, 05:00 UTC

GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not limit the number or duration of commands and uses a blocking socket connection, which allows attackers to cause a denial of service (resource exhaustion) by sending commands and not reading the results.

CVE-2003-0548 gnome vulnerability CVSS: 5.0 27 Aug 2003, 04:00 UTC

The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.

CVE-2003-0549 gnome vulnerability CVSS: 5.0 27 Aug 2003, 04:00 UTC

The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.

CVE-2003-0547 gnome vulnerability CVSS: 2.1 27 Aug 2003, 04:00 UTC

GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file.

CVE-2003-0407 gnome vulnerability CVSS: 10.0 30 Jun 2003, 04:00 UTC

Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.

CVE-2003-0133 gnome vulnerability CVSS: 5.0 05 May 2003, 04:00 UTC

GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.

CVE-2003-0165 gnome vulnerability CVSS: 4.6 02 Apr 2003, 05:00 UTC

Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.

CVE-2003-0080 gnome vulnerability CVSS: 7.5 31 Mar 2003, 05:00 UTC

The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass intended access restrictions if packet forwarding is enabled.

CVE-2003-0070 gnome vulnerability CVSS: 6.8 03 Mar 2003, 05:00 UTC

VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

CVE-2002-1814 gnome vulnerability CVSS: 4.6 31 Dec 2002, 05:00 UTC

Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long command line arguments.

CVE-2001-0928 gnome vulnerability CVSS: 7.5 28 Nov 2001, 05:00 UTC

Buffer overflow in the permitted function of GNOME gtop daemon (libgtop_daemon) in libgtop 1.0.13 and earlier may allow remote attackers to execute arbitrary code via long authentication data.

CVE-2001-0927 gnome vulnerability CVSS: 7.5 27 Nov 2001, 05:00 UTC

Format string vulnerability in the permitted function of GNOME libgtop_daemon in libgtop 1.0.12 and earlier allows remote attackers to execute arbitrary code via an argument that contains format specifiers that are passed into the (1) syslog_message and (2) syslog_io_message functions.

CVE-2001-0084 gnome vulnerability CVSS: 7.2 12 Feb 2001, 05:00 UTC

GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.

CVE-2000-0864 gnome vulnerability CVSS: 6.2 14 Nov 2000, 05:00 UTC

Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change the permissions of arbitrary files and directories, and gain additional privileges, via a symlink attack.

CVE-2000-0504 gnome vulnerability CVSS: 5.0 19 Jun 2000, 04:00 UTC

libICE in XFree86 allows remote attackers to cause a denial of service by specifying a large value which is not properly checked by the SKIP_STRING macro.

CVE-2000-0491 gnome vulnerability CVSS: 10.0 24 May 2000, 04:00 UTC

Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request.

CVE-1999-0990 gnome vulnerability CVSS: 2.1 05 Dec 1999, 05:00 UTC

Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.

CVE-1999-1477 gnome vulnerability CVSS: 7.2 23 Sep 1999, 04:00 UTC

Buffer overflow in GNOME libraries 1.0.8 allows local user to gain root access via a long --espeaker argument in programs such as nethack.