GNOME kayıtları
gnome üreticisine ait 363 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %0,8
- Pre-auth RCE
- 53
- Düzeltme kaydı olan
- %81,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer20
- CWE-20 Improper Input Validation19
- CWE-190 Integer Overflow or Wraparound18
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor15
- CWE-787 Out-of-bounds Write15
- CWE-125 Out-of-bounds Read13
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
363 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-2017-1000083Silahlaştırılmış | backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary comgnome · evince | Yüksek7,8 | — | %51,1 | 5 Eyl 2017 |
46Planlayın | CVE-2017-2885İstismar yok | An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58.gnome · libsoup · CWE-787 | Kritik9,8 | — | %23,5 | 24 Nis 2018 |
46Planlayın | CVE-2008-3533Kavram kanıtı | Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attacgnome · yelp · CWE-134 | Kritik10,0 | — | %19,4 | 18 Ağu 2008 |
45Planlayın | CVE-2000-0491Kavram kanıtı | Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a degnome · gdm | Kritik10,0 | — | %17,8 | 24 May 2000 |
45Planlayın | CVE-2003-0407Kavram kanıtı | Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.gnome · batalla naval | Kritik10,0 | — | %16,4 | 30 Haz 2003 |
43Planlayın | CVE-2004-0888İstismar yok | Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attakde · koffice | Kritik10,0 | — | %9,5 | 27 Oca 2005 |
42Planlayın | CVE-2004-0889İstismar yok | Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of servxpdf · xpdf | Kritik10,0 | — | %6,2 | 27 Oca 2005 |
41Planlayın | CVE-2019-1010238İstismar yok | Gnome Pango 1.42 and later is affected by: Buffer Overflow.gnome · pango · CWE-787 | Kritik9,8 | — | %6,3 | 19 Tem 2019 |
40Planlayın | CVE-2009-3608İstismar yok | Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdfpoppler · poppler · CWE-189 | Kritik9,3 | — | %10,2 | 21 Eki 2009 |
40Planlayın | CVE-2009-3604İstismar yok | The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does kde · kpdf · CWE-399 | Kritik9,3 | — | %8,7 | 21 Eki 2009 |
40Planlayın | CVE-2017-5885İstismar yok | Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remotefedoraproject · fedora · CWE-190 | Kritik9,8 | — | %5,0 | 28 Şub 2017 |
40Planlayın | CVE-2018-16428İstismar yok | In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.gnome · glib · CWE-476 | Kritik9,8 | — | %4,7 | 3 Eyl 2018 |
40Planlayın | CVE-2012-0828İstismar yok | Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause axchat · xchat · CWE-787 | Kritik9,8 | — | %4,3 | 21 Şub 2020 |
40Planlayın | CVE-2018-12910İstismar yok | The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.gnome · libsoup · CWE-125 | Kritik9,8 | — | %4,2 | 5 Tem 2018 |
40Planlayın | CVE-2005-0102İstismar yok | Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrargnome · evolution · CWE-190 | Kritik9,8 | — | %3,2 | 24 Oca 2005 |
40Planlayın | CVE-2016-10727İstismar yok | camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data gnome · evolution · CWE-200 | Kritik9,8 | — | %2,9 | 20 Tem 2018 |
40Planlayın | CVE-2022-27811İstismar yok | GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.gnome · ocrfeeder · CWE-78 | Kritik9,8 | — | %2,8 | 23 Mar 2022 |
40Planlayın | CVE-2019-17266İstismar yok | libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does nognome · libsoup · CWE-125 | Kritik9,8 | — | %2,8 | 6 Eki 2019 |
40Planlayın | CVE-2019-12450İstismar yok | file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is gnome · glib · CWE-276 | Kritik9,8 | — | %2,6 | 29 May 2019 |
40Planlayın | CVE-2011-2897İstismar yok | gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flawgnome · gdk-pixbuf · CWE-20 | Kritik9,8 | — | %1,9 | 12 Kas 2019 |
40Planlayın | CVE-2018-12422İstismar yok | addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger gnome · evolution · CWE-119 | Kritik9,8 | — | %1,8 | 15 Haz 2018 |
39İzleyin | CVE-2011-3193İstismar yok | Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pangoqt · qt · CWE-787 | Kritik9,3 | — | %7,3 | 15 Haz 2012 |
39İzleyin | CVE-2008-1109İstismar yok | Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION propergnome · evolution · CWE-119 | Kritik9,3 | — | %5,7 | 4 Haz 2008 |
39İzleyin | CVE-2017-1000044İstismar yok | gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when regnome · gtk-vnc · CWE-119 | Kritik9,8 | — | %1,6 | 17 Tem 2017 |
39İzleyin | CVE-2024-52533İstismar yok | gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufgnome · glib · CWE-120 | Kritik9,8 | — | %1,3 | 11 Kas 2024 |
- CVE-2017-100008346Planlayın
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary com
YüksekCVSS 7,8SilahlaştırılmışEPSS %51gnome · evince5 Eyl 2017
- CVE-2017-288546Planlayın
An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58.
KritikCVSS 9,8İstismar yokEPSS %24gnome · libsoup24 Nis 2018
- CVE-2008-353346Planlayın
Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attac
KritikCVSS 10,0Kavram kanıtıEPSS %19gnome · yelp18 Ağu 2008
- CVE-2000-049145Planlayın
Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a de
KritikCVSS 10,0Kavram kanıtıEPSS %18gnome · gdm24 May 2000
- CVE-2003-040745Planlayın
Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.
KritikCVSS 10,0Kavram kanıtıEPSS %16gnome · batalla naval30 Haz 2003
- CVE-2004-088843Planlayın
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote atta
KritikCVSS 10,0İstismar yokEPSS %10kde · koffice27 Oca 2005
- CVE-2004-088942Planlayın
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of serv
KritikCVSS 10,0İstismar yokEPSS %6xpdf · xpdf27 Oca 2005
- CVE-2019-101023841Planlayın
Gnome Pango 1.42 and later is affected by: Buffer Overflow.
KritikCVSS 9,8İstismar yokEPSS %6gnome · pango19 Tem 2019
- CVE-2009-360840Planlayın
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf
KritikCVSS 9,3İstismar yokEPSS %10poppler · poppler21 Eki 2009
- CVE-2009-360440Planlayın
The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does
KritikCVSS 9,3İstismar yokEPSS %9kde · kpdf21 Eki 2009
- CVE-2017-588540Planlayın
Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote
KritikCVSS 9,8İstismar yokEPSS %5fedoraproject · fedora28 Şub 2017
- CVE-2018-1642840Planlayın
In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.
KritikCVSS 9,8İstismar yokEPSS %5gnome · glib3 Eyl 2018
- CVE-2012-082840Planlayın
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a
KritikCVSS 9,8İstismar yokEPSS %4xchat · xchat21 Şub 2020
- CVE-2018-1291040Planlayın
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
KritikCVSS 9,8İstismar yokEPSS %4gnome · libsoup5 Tem 2018
- CVE-2005-010240Planlayın
Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrar
KritikCVSS 9,8İstismar yokEPSS %3gnome · evolution24 Oca 2005
- CVE-2016-1072740Planlayın
camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data
KritikCVSS 9,8İstismar yokEPSS %3gnome · evolution20 Tem 2018
- CVE-2022-2781140Planlayın
GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.
KritikCVSS 9,8İstismar yokEPSS %3gnome · ocrfeeder23 Mar 2022
- CVE-2019-1726640Planlayın
libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does no
KritikCVSS 9,8İstismar yokEPSS %3gnome · libsoup6 Eki 2019
- CVE-2019-1245040Planlayın
file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is
KritikCVSS 9,8İstismar yokEPSS %3gnome · glib29 May 2019
- CVE-2011-289740Planlayın
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw
KritikCVSS 9,8İstismar yokEPSS %2gnome · gdk-pixbuf12 Kas 2019
- CVE-2018-1242240Planlayın
addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger
KritikCVSS 9,8İstismar yokEPSS %2gnome · evolution15 Haz 2018
- CVE-2011-319339İzleyin
Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango
KritikCVSS 9,3İstismar yokEPSS %7qt · qt15 Haz 2012
- CVE-2008-110939İzleyin
Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION proper
KritikCVSS 9,3İstismar yokEPSS %6gnome · evolution4 Haz 2008
- CVE-2017-100004439İzleyin
gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when re
KritikCVSS 9,8İstismar yokEPSS %2gnome · gtk-vnc17 Tem 2017
- CVE-2024-5253339İzleyin
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not suf
KritikCVSS 9,8İstismar yokEPSS %1gnome · glib11 Kas 2024