Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

432 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.4%—Gnome Epiphany17/7/201717/6/2026
GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfiltration of stored passwords for a selected set of websites.
ModificadaAlta (7.5)1.2%—Gnome Shotwell17/7/201717/6/2026
Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext transmission
ModificadaMedia (5.5)0.32%—Gnome-session11/7/201717/6/2026
Bad reference counting in the context of accept_ice_connection() in gsm-xsmp-server.c in old versions of gnome-session up until version 2.29.92 allows a local attacker to establish ICE connections to gnome-session with invalid authentication data (an invalid magic cookie). Each failed authentication attempt will leak…
ModificadaMedia (6.5)13%💥 ExploitGnome LibcrocoOpensuse Leap12/6/201717/6/2026
The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file.
ModificadaMedia (6.5)3.8%—Gnome LibcrocoOpensuse Leap12/6/201717/6/2026
The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (memory allocation error) via a crafted CSS file.
ModificadaAlta (8.1)3.0%—Gnome-shell27/4/201717/6/2026
gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what…
ModificadaAlta (7.8)2.0%—Gnome Libcroco19/4/201717/6/2026
The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable values of type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CSS file.…
ModificadaMedia (5.5)2.0%—Gnome Libcroco19/4/201717/6/2026
The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.
ModificadaMedia (5.5)1.9%—Gnome Gdk-pixbufFedoraproject FedoraDebian Linux10/3/201717/6/2026
The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (infinite loop) via a large TIFF file.
ModificadaAlta (7.1)1.9%—Gnome Gdk-pixbufFedoraproject FedoraDebian Linux10/3/201717/6/2026
Integer underflow in the load_resources function in io-icns.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (out-of-bounds read and program crash) via a crafted image entry size in an ICO file.
ModificadaMedia (5.5)2.0%—Gnome Gdk-pixbufFedoraproject FedoraDebian Linux10/3/201717/6/2026
Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, which triggers an out-of-bounds read, related to compiler optimizations.
ModificadaAlta (7.5)3.5%—Gnome Gdk-pixbufFedoraproject Fedora10/3/201717/6/2026
gdk-pixbuf-thumbnailer.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to printing an error message.
ModificadaCrítica (9.8)5.0%—Fedoraproject FedoraGnome Gtk-vnc28/2/201717/6/2026
Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.
ModificadaAlta (7.8)2.2%—Fedoraproject FedoraGnome Gtk-vnc28/2/201717/6/2026
gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.
ModificadaMedia (5.5)1.4%—Gnome Librsvg3/2/201717/6/2026
The rsvg_pattern_fix_fallback function in rsvg-paint_server.c in librsvg2 2.40.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted svg file.
ModificadaMedia (5.5)1.3%—Gnome Libgsf8/12/201617/6/2026
An error within the "tar_directory_for_file()" function (gsf-infile-tar.c) in GNOME Structured File Library before 1.14.41 can be exploited to trigger a Null pointer dereference and subsequently cause a crash via a crafted TAR file.
ModificadaBaja (3.7)0.87%—Gnome ShotwellRedhat Enterprise Linux25/10/201617/6/2026
Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.
ModificadaAlta (7.5)3.9%—Canonical Ubuntu LinuxGnome Gdk-pixbufOpensuse LeapOpensuse3/10/201617/6/2026
The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via crafted dimensions in an ICO file.
ModificadaAlta (7.5)18%💥 ExploitFedoraproject FedoraOpensuse LeapOpensuseCanonical Ubuntu Linux+17/9/201617/6/2026
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.
ModificadaAlta (7.8)2.8%—Gnome Gdk-pixbufDebian Linux1/6/201617/6/2026
Multiple integer overflows in the (1) pixops_composite_nearest, (2) pixops_composite_color_nearest, and (3) pixops_process functions in pixops/pixops.c in gdk-pixbuf before 2.33.1 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image, which…
ModificadaAlta (7.5)2.4%—Gnome LibrsvgDebian LinuxOpensuse LeapOpensuse20/5/201617/6/2026
The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via circular definitions in an SVG document.
ModificadaAlta (7.5)2.4%—Debian LinuxGnome Librsvg20/5/201617/6/2026
librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via cyclic references in an SVG document.
ModificadaAlta (7.5)2.0%—Gnome Librsvg20/5/201617/6/2026
The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via an odd number of elements in a coordinate pair in an SVG document.
ModificadaMedia (6.5)0.76%—Canonical Ubuntu LinuxXchatXchat GnomeHexchat Project Hexchat21/4/201617/6/2026
The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
ModificadaAlta (7.2)0.41%—Fedoraproject FedoraGnome Display Manager24/11/201517/6/2026
GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the Escape key.
Orbitaley — Vulnerabilidades