Записи GNOME
363 опубликованных записей вендора gnome.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 0,8 %
- Pre-auth RCE
- 53
- С записью об исправлении
- 81,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer20
- CWE-20 Improper Input Validation19
- CWE-190 Integer Overflow or Wraparound18
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor15
- CWE-787 Out-of-bounds Write15
- CWE-125 Out-of-bounds Read13
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
363 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
46В плане | CVE-2017-1000083Готовый эксплойт | backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary comgnome · evince | Высокая7,8 | — | 51,1 % | 5 сент. 2017 г. |
46В плане | CVE-2017-2885Эксплойта нет | An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58.gnome · libsoup · CWE-787 | Критическая9,8 | — | 23,5 % | 24 апр. 2018 г. |
46В плане | CVE-2008-3533Proof of concept | Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attacgnome · yelp · CWE-134 | Критическая10,0 | — | 19,4 % | 18 авг. 2008 г. |
45В плане | CVE-2000-0491Proof of concept | Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a degnome · gdm | Критическая10,0 | — | 17,8 % | 24 мая 2000 г. |
45В плане | CVE-2003-0407Proof of concept | Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.gnome · batalla naval | Критическая10,0 | — | 16,4 % | 30 июн. 2003 г. |
43В плане | CVE-2004-0888Эксплойта нет | Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attakde · koffice | Критическая10,0 | — | 9,5 % | 27 янв. 2005 г. |
42В плане | CVE-2004-0889Эксплойта нет | Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of servxpdf · xpdf | Критическая10,0 | — | 6,2 % | 27 янв. 2005 г. |
41В плане | CVE-2019-1010238Эксплойта нет | Gnome Pango 1.42 and later is affected by: Buffer Overflow.gnome · pango · CWE-787 | Критическая9,8 | — | 6,3 % | 19 июл. 2019 г. |
40В плане | CVE-2009-3608Эксплойта нет | Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdfpoppler · poppler · CWE-189 | Критическая9,3 | — | 10,2 % | 21 окт. 2009 г. |
40В плане | CVE-2009-3604Эксплойта нет | The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does kde · kpdf · CWE-399 | Критическая9,3 | — | 8,7 % | 21 окт. 2009 г. |
40В плане | CVE-2017-5885Эксплойта нет | Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remotefedoraproject · fedora · CWE-190 | Критическая9,8 | — | 5,0 % | 28 февр. 2017 г. |
40В плане | CVE-2018-16428Эксплойта нет | In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.gnome · glib · CWE-476 | Критическая9,8 | — | 4,7 % | 3 сент. 2018 г. |
40В плане | CVE-2012-0828Эксплойта нет | Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause axchat · xchat · CWE-787 | Критическая9,8 | — | 4,3 % | 21 февр. 2020 г. |
40В плане | CVE-2018-12910Эксплойта нет | The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.gnome · libsoup · CWE-125 | Критическая9,8 | — | 4,2 % | 5 июл. 2018 г. |
40В плане | CVE-2005-0102Эксплойта нет | Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrargnome · evolution · CWE-190 | Критическая9,8 | — | 3,2 % | 24 янв. 2005 г. |
40В плане | CVE-2016-10727Эксплойта нет | camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data gnome · evolution · CWE-200 | Критическая9,8 | — | 2,9 % | 20 июл. 2018 г. |
40В плане | CVE-2022-27811Эксплойта нет | GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.gnome · ocrfeeder · CWE-78 | Критическая9,8 | — | 2,8 % | 23 мар. 2022 г. |
40В плане | CVE-2019-17266Эксплойта нет | libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does nognome · libsoup · CWE-125 | Критическая9,8 | — | 2,8 % | 6 окт. 2019 г. |
40В плане | CVE-2019-12450Эксплойта нет | file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is gnome · glib · CWE-276 | Критическая9,8 | — | 2,6 % | 29 мая 2019 г. |
40В плане | CVE-2011-2897Эксплойта нет | gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flawgnome · gdk-pixbuf · CWE-20 | Критическая9,8 | — | 1,9 % | 12 нояб. 2019 г. |
40В плане | CVE-2018-12422Эксплойта нет | addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger gnome · evolution · CWE-119 | Критическая9,8 | — | 1,8 % | 15 июн. 2018 г. |
39Наблюдать | CVE-2011-3193Эксплойта нет | Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pangoqt · qt · CWE-787 | Критическая9,3 | — | 7,3 % | 15 июн. 2012 г. |
39Наблюдать | CVE-2008-1109Эксплойта нет | Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION propergnome · evolution · CWE-119 | Критическая9,3 | — | 5,7 % | 4 июн. 2008 г. |
39Наблюдать | CVE-2017-1000044Эксплойта нет | gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when regnome · gtk-vnc · CWE-119 | Критическая9,8 | — | 1,6 % | 17 июл. 2017 г. |
39Наблюдать | CVE-2024-52533Эксплойта нет | gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufgnome · glib · CWE-120 | Критическая9,8 | — | 1,3 % | 11 нояб. 2024 г. |
- CVE-2017-100008346В плане
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary com
ВысокаяCVSS 7,8Готовый эксплойтEPSS 51 %gnome · evince5 сент. 2017 г.
- CVE-2017-288546В плане
An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58.
КритическаяCVSS 9,8Эксплойта нетEPSS 24 %gnome · libsoup24 апр. 2018 г.
- CVE-2008-353346В плане
Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attac
КритическаяCVSS 10,0Proof of conceptEPSS 19 %gnome · yelp18 авг. 2008 г.
- CVE-2000-049145В плане
Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a de
КритическаяCVSS 10,0Proof of conceptEPSS 18 %gnome · gdm24 мая 2000 г.
- CVE-2003-040745В плане
Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.
КритическаяCVSS 10,0Proof of conceptEPSS 16 %gnome · batalla naval30 июн. 2003 г.
- CVE-2004-088843В плане
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote atta
КритическаяCVSS 10,0Эксплойта нетEPSS 10 %kde · koffice27 янв. 2005 г.
- CVE-2004-088942В плане
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of serv
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %xpdf · xpdf27 янв. 2005 г.
- CVE-2019-101023841В плане
Gnome Pango 1.42 and later is affected by: Buffer Overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %gnome · pango19 июл. 2019 г.
- CVE-2009-360840В плане
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf
КритическаяCVSS 9,3Эксплойта нетEPSS 10 %poppler · poppler21 окт. 2009 г.
- CVE-2009-360440В плане
The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does
КритическаяCVSS 9,3Эксплойта нетEPSS 9 %kde · kpdf21 окт. 2009 г.
- CVE-2017-588540В плане
Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %fedoraproject · fedora28 февр. 2017 г.
- CVE-2018-1642840В плане
In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %gnome · glib3 сент. 2018 г.
- CVE-2012-082840В плане
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %xchat · xchat21 февр. 2020 г.
- CVE-2018-1291040В плане
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %gnome · libsoup5 июл. 2018 г.
- CVE-2005-010240В плане
Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrar
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %gnome · evolution24 янв. 2005 г.
- CVE-2016-1072740В плане
camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %gnome · evolution20 июл. 2018 г.
- CVE-2022-2781140В плане
GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %gnome · ocrfeeder23 мар. 2022 г.
- CVE-2019-1726640В плане
libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does no
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %gnome · libsoup6 окт. 2019 г.
- CVE-2019-1245040В плане
file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %gnome · glib29 мая 2019 г.
- CVE-2011-289740В плане
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gnome · gdk-pixbuf12 нояб. 2019 г.
- CVE-2018-1242240В плане
addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gnome · evolution15 июн. 2018 г.
- CVE-2011-319339Наблюдать
Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %qt · qt15 июн. 2012 г.
- CVE-2008-110939Наблюдать
Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION proper
КритическаяCVSS 9,3Эксплойта нетEPSS 6 %gnome · evolution4 июн. 2008 г.
- CVE-2017-100004439Наблюдать
gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when re
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gnome · gtk-vnc17 июл. 2017 г.
- CVE-2024-5253339Наблюдать
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not suf
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gnome · glib11 нояб. 2024 г.