Lucene search

K

Gnome Security Vulnerabilities

cve
cve

CVE-2023-5664

The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ggpkg' shortcode in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated....

6.4CVSS

5.3AI Score

0.001EPSS

2023-11-22 04:15 PM
55
cve
cve

CVE-2023-43090

A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot...

5.5CVSS

5.1AI Score

0.0004EPSS

2023-09-22 06:15 AM
55
cve
cve

CVE-2023-36250

CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating a new...

7.8CVSS

7.8AI Score

0.001EPSS

2023-09-14 05:15 PM
9
cve
cve

CVE-2020-24904

An issue was discovered in attach parameter in GNOME Gmail version 2.5.4, allows remote attackers to gain sensitive information via crafted "mailto"...

6.5CVSS

6.5AI Score

0.001EPSS

2023-08-11 02:15 PM
10
cve
cve

CVE-2017-11171

Bad reference counting in the context of accept_ice_connection() in gsm-xsmp-server.c in old versions of gnome-session up until version 2.29.92 allows a local attacker to establish ICE connections to gnome-session with invalid authentication data (an invalid magic cookie). Each failed...

5.5CVSS

5.3AI Score

0.0004EPSS

2022-10-03 04:23 PM
28
cve
cve

CVE-2005-2944

The perform_file_save function in GNOME Workstation Command Center (gwcc) 0.9.6 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the gwcc_out.txt temporary...

6.8AI Score

0.0004EPSS

2022-10-03 04:22 PM
19
cve
cve

CVE-2010-4000

gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working...

6.6AI Score

0.0004EPSS

2022-10-03 04:21 PM
23
cve
cve

CVE-2013-4169

GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on...

6.1AI Score

0.0004EPSS

2022-10-03 04:14 PM
24
cve
cve

CVE-2013-1050

The default configuration in gnome-screensaver 3.5.4 through 3.6.0 sets the AutostartCondition line to fallback mode in the .desktop file, which prevents the program from starting automatically after login and allows physically proximate attackers to bypass screen locking and access an unattended.....

6.5AI Score

0.001EPSS

2022-10-03 04:14 PM
26
cve
cve

CVE-2021-42522

There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrect use of libxml2 API. The vendor forgot to call 'g_free()' to release the return value of...

7.5CVSS

7.2AI Score

0.002EPSS

2022-08-25 06:15 PM
20
cve
cve

CVE-2021-3982

Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privilege permissions, may take advantage of the way CAP_SYS_NICE is currently implemented and eventually load code to increase its process scheduler priority leading to...

5.5CVSS

5.6AI Score

0.0004EPSS

2022-04-29 05:15 PM
70
cve
cve

CVE-2021-20315

A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enabled. This flaw allows a physical attacker who has access to a locked system to kill existing applications and start...

6.1CVSS

6AI Score

0.001EPSS

2022-02-18 06:15 PM
39
cve
cve

CVE-2021-28650

autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete....

5.5CVSS

6.2AI Score

0.001EPSS

2021-03-17 06:15 AM
193
4
cve
cve

CVE-2020-14391

A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat...

5.5CVSS

5.8AI Score

0.0004EPSS

2021-02-08 11:15 PM
114
cve
cve

CVE-2020-36241

autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction...

5.5CVSS

5.9AI Score

0.001EPSS

2021-02-05 02:15 PM
211
cve
cve

CVE-2020-27837

A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more...

6.4CVSS

6AI Score

0.001EPSS

2020-12-28 07:15 PM
63
cve
cve

CVE-2020-16125

gdm3 versions before 3.36.2 or 3.38.2 would start gnome-initial-setup if gdm3 can't contact the accountservice service via dbus in a timely manner; on Ubuntu (and potentially derivatives) this could be be chained with an additional issue that could allow a local user to create a new privileged...

7.2CVSS

6.4AI Score

0.001EPSS

2020-11-10 05:15 AM
196
1
cve
cve

CVE-2020-17489

An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible....

4.3CVSS

4.4AI Score

0.001EPSS

2020-08-11 09:15 PM
167
2
cve
cve

CVE-2012-6111

gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync...

7.5CVSS

7.5AI Score

0.013EPSS

2019-12-20 03:15 PM
29
cve
cve

CVE-2019-19308

In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing a TTF font file that lacks a name section (due to a g_strconcat call that returns...

5.5CVSS

5.3AI Score

0.001EPSS

2019-11-27 03:15 PM
31
cve
cve

CVE-2012-5535

gnome-system-log polkit policy allows arbitrary files on the system to be...

7.5CVSS

7.3AI Score

0.002EPSS

2019-11-25 02:15 PM
18
cve
cve

CVE-2016-1000002

gdm3 3.14.2 and possibly later has an information leak before screen...

2.4CVSS

3.7AI Score

0.001EPSS

2019-11-05 02:15 PM
37
cve
cve

CVE-2019-11460

An issue was discovered in GNOME gnome-desktop 3.26, 3.28, and 3.30 prior to 3.30.2.2, and 3.32 prior to 3.32.1.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's...

9CVSS

8.3AI Score

0.002EPSS

2019-04-22 10:29 PM
116
cve
cve

CVE-2018-20781

In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in...

7.8CVSS

7.5AI Score

0.0005EPSS

2019-02-12 05:29 PM
32
cve
cve

CVE-2019-3820

It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other...

4.3CVSS

4.5AI Score

0.001EPSS

2019-02-06 08:29 PM
418
cve
cve

CVE-2019-3825

A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by selecting the timed login user and waiting for the timer to expire, at which time they would gain access to the logged-in user's...

6.4CVSS

5.4AI Score

0.001EPSS

2019-02-06 08:29 PM
127
cve
cve

CVE-2018-19358

GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that this occurs because available D-Bus protection mechanisms (involving the...

7.8CVSS

6.7AI Score

0.001EPSS

2018-11-18 07:29 PM
45
cve
cve

CVE-2018-14424

The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code...

7.8CVSS

7.4AI Score

0.0004EPSS

2018-08-14 06:29 PM
53
cve
cve

CVE-2017-12164

A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as another user' to unlock their...

6.4CVSS

6AI Score

0.001EPSS

2018-07-26 04:29 PM
41
cve
cve

CVE-2017-15131

It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise...

7.8CVSS

7.5AI Score

0.0004EPSS

2018-01-09 09:29 PM
57
cve
cve

CVE-2017-11421

gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue. There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory containing a .msi file with VBScript code in its...

7.8CVSS

7.7AI Score

0.001EPSS

2017-07-18 07:29 PM
27
cve
cve

CVE-2017-8288

gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you...

8.1CVSS

8AI Score

0.004EPSS

2017-04-27 12:59 AM
39
cve
cve

CVE-2016-6855

Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to...

7.5CVSS

7.1AI Score

0.022EPSS

2016-09-07 06:59 PM
66
4
cve
cve

CVE-2013-7449

The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid...

6.5CVSS

6.3AI Score

0.001EPSS

2016-04-21 02:59 PM
21
2
cve
cve

CVE-2015-7217

The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the TGA decoder, which allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted Truevision TGA...

6.8AI Score

0.031EPSS

2015-12-16 11:59 AM
39
cve
cve

CVE-2015-7216

The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted JPEG 2000...

7.6AI Score

0.028EPSS

2015-12-16 11:59 AM
48
cve
cve

CVE-2015-7496

GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the Escape...

6.3AI Score

0.001EPSS

2015-11-24 08:59 PM
30
cve
cve

CVE-2014-7300

GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging.....

7.2AI Score

0.001EPSS

2014-12-25 09:59 PM
26
cve
cve

CVE-2011-2198

The "insert-blank-characters" capability in caps.c in gnome-terminal (vte) before 0.28.1 allows remote authenticated users to cause a denial of service (CPU and memory consumption and crash) via a crafted file, as demonstrated by a file containing the string...

5.9AI Score

0.009EPSS

2014-05-21 02:55 PM
31
cve
cve

CVE-2013-7273

GNOME Display Manager (gdm) 3.4.1 and earlier, when disable-user-list is set to true, allows local users to cause a denial of service (unable to login) by pressing the cancel button after entering a user...

6.4AI Score

0.0004EPSS

2014-04-29 02:38 PM
18
cve
cve

CVE-2013-7221

The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Enter a Command" dialog, which allows physically proximate attackers to execute arbitrary commands by leveraging an unattended...

7.6AI Score

0.001EPSS

2014-04-29 02:38 PM
17
cve
cve

CVE-2013-7220

js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with the keyboard focus on the Activities...

7.6AI Score

0.001EPSS

2014-04-29 02:38 PM
19
cve
cve

CVE-2013-1799

Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the...

5.9AI Score

0.003EPSS

2013-04-02 03:23 AM
23
cve
cve

CVE-2013-0240

Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the....

5.8AI Score

0.002EPSS

2013-04-02 03:22 AM
23
cve
cve

CVE-2010-2387

vicious-extensions/ve-misc.c in GNOME Display Manager (gdm) 2.20.x before 2.20.11, when GDM debug is enabled, logs the user password when it contains invalid UTF8 encoded characters, which might allow local users to gain privileges by reading the information from syslog...

6.6AI Score

0.0004EPSS

2012-12-21 05:46 AM
21
cve
cve

CVE-2012-3466

GNOME gnome-keyring 3.4.0 through 3.4.1, when gpg-cache-method is set to "idle" or "timeout," does not properly limit the amount of time a passphrase is cached, which allows attackers to have an unspecified impact via unknown attack...

6.5AI Score

0.001EPSS

2012-10-22 11:55 PM
25
cve
cve

CVE-2012-4427

The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a crafted web...

6.9AI Score

0.024EPSS

2012-10-01 03:26 AM
23
cve
cve

CVE-2010-3357

gnome-subtitles 1.0 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working...

6.2AI Score

0.0004EPSS

2010-10-20 06:00 PM
27
cve
cve

CVE-2010-2713

The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows remote attackers to execute arbitrary commands or obtain potentially sensitive information via a...

7.1AI Score

0.052EPSS

2010-08-05 06:17 PM
33
cve
cve

CVE-2009-1276

XScreenSaver in Sun Solaris 10 and OpenSolaris before snv_109, and Solaris 8 and 9 with GNOME 2.0 or 2.0.2, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, as demonstrated by Thunderbird new-mail...

5.8AI Score

0.001EPSS

2009-04-09 03:08 PM
27
Total number of security vulnerabilities60