gnome
341 tracked vulnerabilities.
CVE-2025-3155
HIGH
Yelp - Arbitrary Script Execution via Help Document
Apr 03, 2025
CVSS 7.4
EPSS 0.01
CVE-2025-2784
HIGH
libsoup < 3.6.5 - Heap Buffer Over-Read via skip_insight_whitespace()
Apr 03, 2025
CVSS 7.0
EPSS 0.00
CVE-2024-52533
CRITICAL
GNOME GLib < 2.82.1 - Buffer Overflow in SOCKS4 Proxy Connection Message Handling
Nov 11, 2024
CVSS 9.8
EPSS 0.03
CVE-2024-52532
HIGH
GNOME libsoup < 3.6.1 - Denial of Service via WebSocket Data Parsing
Nov 11, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-52531
MEDIUM
GNOME libsoup < 3.6.1 - Out-of-bounds Write via soup_header_parse_param_list_strict
Nov 11, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-52530
HIGH
GNOME libsoup < 3.6.0 - HTTP Request Smuggling via Null Byte in Header Names
Nov 11, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-42415
HIGH
GNOME Project G Structured File Library <1.14.52 - RCE
Oct 03, 2024
CVSS 8.4
EPSS 0.00
CVE-2024-36474
HIGH
GNOME Project G Structured File Library <1.14.52 - RCE
Oct 03, 2024
CVSS 8.4
EPSS 0.00
CVE-2024-34397
MEDIUM
GNOME GLib <2.78.5, 2.79.x, 2.80.x - Info Disclosure
May 07, 2024
CVSS 5.2
EPSS 0.00
CVE-2023-5616
MEDIUM
gnome-control-center 1.3-1.3.36.5 - Authentication Bypass via SSH Remote Login Status Mismanagement
Apr 15, 2025
CVSS 4.9
EPSS 0.00
CVE-2023-43091
CRITICAL
GNOME Maps 43.0-43.6 - Code Injection via service.json Configuration File
Nov 17, 2024
CVSS 9.8
EPSS 0.00
CVE-2023-5557
HIGH
tracker_miners < 3.3.2 - Sandbox Escape via Malicious File
Oct 13, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-43090
MEDIUM
GNOME Shell 43-43.9 - Unauthenticated Information Disclosure via Lock Screen Screenshot Tool
Sep 22, 2023
CVSS 5.5
EPSS 0.00
CVE-2023-32665
MEDIUM
GLib < 2.74.4 - Denial of Service via GVariant Deserialization
Sep 14, 2023
CVSS 5.5
EPSS 0.00
CVE-2023-32643
MEDIUM
GLib < 2.75.1 - Heap-based Buffer Overflow in GVariant Deserialization
Sep 14, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-32636
MEDIUM
glib < 2.74.4 - Denial of Service via GVariant Deserialization Offset Table Validation
Sep 14, 2023
CVSS 4.7
EPSS 0.00
CVE-2023-32611
MEDIUM
GLib < 2.74.2 - Denial of Service via GVariant Deserialization
Sep 14, 2023
CVSS 5.5
EPSS 0.00
CVE-2023-29499
MEDIUM
GLib < 2.74.4 - Denial of Service via GVariant Deserialization
Sep 14, 2023
CVSS 5.5
EPSS 0.00
CVE-2023-36250
HIGH
GNOME time tracker <3.0.2 - Code Injection
Sep 14, 2023
CVSS 7.8
EPSS 0.04
CVE-2023-38633
MEDIUM
librsvg 2.42.3-2.46.6 - Directory Traversal via URL Decoder
Jul 22, 2023
CVSS 5.5
EPSS 0.44
CVE-2023-26081
HIGH
Epiphany < 43.1 - Password Exfiltration via Autofill in Sandboxed Contexts
Feb 20, 2023
CVSS 7.5
EPSS 0.00
CVE-2022-1736
CRITICAL
Ubuntu Gnome-control-center - Info Disclosure
Jan 31, 2025
CVSS 9.8
EPSS 0.01
CVE-2022-48622
HIGH
GNOME GdkPixbuf < 2.42.10 - Heap Memory Corruption via Crafted ANI File
Jan 26, 2024
CVSS 7.8
EPSS 0.00
CVE-2022-37290
MEDIUM
GNOME Nautilus 42.2 - Denial of Service via Pasted ZIP Archive
Nov 14, 2022
CVSS 5.5
EPSS 0.00
CVE-2022-29536
HIGH
GNOME Epiphany < 41.4 and 42.x < 42.2 - Out-of-bounds Write via Long Page Title
Apr 20, 2022
CVSS 7.5
EPSS 0.00
Products
glib 26
libsoup 24
evolution 21
gdk-pixbuf 20
gdm 15
gtk 15
epiphany 13
networkmanager 12
gdkpixbuf 11
gnome-shell 11
screensaver 11
gnome_display_manager 10
librsvg 10
evince 7
pango 6
gpdf 5
gvfs 5
libcroco 5
nautilus 4
balsa 3
evolution-data-server 3
file-roller 3
gnumeric 3
gthumb 3
gtk-vnc 3
libgsf 3
libgxps 3
Gdk-Pixbuf 2
control_center 2
dwarf_http_server 2
Quick Filters