gnome

341 tracked vulnerabilities.

CVE-2025-3155 HIGH
Yelp - Arbitrary Script Execution via Help Document
Apr 03, 2025
CVSS 7.4
EPSS 0.01
CVE-2025-2784 HIGH
libsoup < 3.6.5 - Heap Buffer Over-Read via skip_insight_whitespace()
Apr 03, 2025
CVSS 7.0
EPSS 0.00
CVE-2024-52533 CRITICAL
GNOME GLib < 2.82.1 - Buffer Overflow in SOCKS4 Proxy Connection Message Handling
Nov 11, 2024
CVSS 9.8
EPSS 0.03
CVE-2024-52532 HIGH
GNOME libsoup < 3.6.1 - Denial of Service via WebSocket Data Parsing
Nov 11, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-52531 MEDIUM
GNOME libsoup < 3.6.1 - Out-of-bounds Write via soup_header_parse_param_list_strict
Nov 11, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-52530 HIGH
GNOME libsoup < 3.6.0 - HTTP Request Smuggling via Null Byte in Header Names
Nov 11, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-42415 HIGH
GNOME Project G Structured File Library <1.14.52 - RCE
Oct 03, 2024
CVSS 8.4
EPSS 0.00
CVE-2024-36474 HIGH
GNOME Project G Structured File Library <1.14.52 - RCE
Oct 03, 2024
CVSS 8.4
EPSS 0.00
CVE-2024-34397 MEDIUM
GNOME GLib <2.78.5, 2.79.x, 2.80.x - Info Disclosure
May 07, 2024
CVSS 5.2
EPSS 0.00
CVE-2023-5616 MEDIUM
gnome-control-center 1.3-1.3.36.5 - Authentication Bypass via SSH Remote Login Status Mismanagement
Apr 15, 2025
CVSS 4.9
EPSS 0.00
CVE-2023-43091 CRITICAL
GNOME Maps 43.0-43.6 - Code Injection via service.json Configuration File
Nov 17, 2024
CVSS 9.8
EPSS 0.00
CVE-2023-5557 HIGH
tracker_miners < 3.3.2 - Sandbox Escape via Malicious File
Oct 13, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-43090 MEDIUM
GNOME Shell 43-43.9 - Unauthenticated Information Disclosure via Lock Screen Screenshot Tool
Sep 22, 2023
CVSS 5.5
EPSS 0.00
CVE-2023-32665 MEDIUM
GLib < 2.74.4 - Denial of Service via GVariant Deserialization
Sep 14, 2023
CVSS 5.5
EPSS 0.00
CVE-2023-32643 MEDIUM
GLib < 2.75.1 - Heap-based Buffer Overflow in GVariant Deserialization
Sep 14, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-32636 MEDIUM
glib < 2.74.4 - Denial of Service via GVariant Deserialization Offset Table Validation
Sep 14, 2023
CVSS 4.7
EPSS 0.00
CVE-2023-32611 MEDIUM
GLib < 2.74.2 - Denial of Service via GVariant Deserialization
Sep 14, 2023
CVSS 5.5
EPSS 0.00
CVE-2023-29499 MEDIUM
GLib < 2.74.4 - Denial of Service via GVariant Deserialization
Sep 14, 2023
CVSS 5.5
EPSS 0.00
CVE-2023-36250 HIGH
GNOME time tracker <3.0.2 - Code Injection
Sep 14, 2023
CVSS 7.8
EPSS 0.04
CVE-2023-38633 MEDIUM
librsvg 2.42.3-2.46.6 - Directory Traversal via URL Decoder
Jul 22, 2023
CVSS 5.5
EPSS 0.44
CVE-2023-26081 HIGH
Epiphany < 43.1 - Password Exfiltration via Autofill in Sandboxed Contexts
Feb 20, 2023
CVSS 7.5
EPSS 0.00
CVE-2022-1736 CRITICAL
Ubuntu Gnome-control-center - Info Disclosure
Jan 31, 2025
CVSS 9.8
EPSS 0.01
CVE-2022-48622 HIGH
GNOME GdkPixbuf < 2.42.10 - Heap Memory Corruption via Crafted ANI File
Jan 26, 2024
CVSS 7.8
EPSS 0.00
CVE-2022-37290 MEDIUM
GNOME Nautilus 42.2 - Denial of Service via Pasted ZIP Archive
Nov 14, 2022
CVSS 5.5
EPSS 0.00
CVE-2022-29536 HIGH
GNOME Epiphany < 41.4 and 42.x < 42.2 - Out-of-bounds Write via Long Page Title
Apr 20, 2022
CVSS 7.5
EPSS 0.00