Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
432 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.4% | — | Gnome Epiphany | 17/7/2017 | 17/6/2026 | GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfiltration of stored passwords for a selected set of websites. | |
| Modificada | Alta (7.5) | 1.2% | — | Gnome Shotwell | 17/7/2017 | 17/6/2026 | Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext transmission | |
| Modificada | Media (5.5) | 0.32% | — | Gnome-session | 11/7/2017 | 17/6/2026 | Bad reference counting in the context of accept_ice_connection() in gsm-xsmp-server.c in old versions of gnome-session up until version 2.29.92 allows a local attacker to establish ICE connections to gnome-session with invalid authentication data (an invalid magic cookie). Each failed authentication attempt will leak… | |
| Modificada | Media (6.5) | 13% | 💥 Exploit | Gnome LibcrocoOpensuse Leap | 12/6/2017 | 17/6/2026 | The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file. | |
| Modificada | Media (6.5) | 3.8% | — | Gnome LibcrocoOpensuse Leap | 12/6/2017 | 17/6/2026 | The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (memory allocation error) via a crafted CSS file. | |
| Modificada | Alta (8.1) | 3.0% | — | Gnome-shell | 27/4/2017 | 17/6/2026 | gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what… | |
| Modificada | Alta (7.8) | 2.0% | — | Gnome Libcroco | 19/4/2017 | 17/6/2026 | The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable values of type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CSS file.… | |
| Modificada | Media (5.5) | 2.0% | — | Gnome Libcroco | 19/4/2017 | 17/6/2026 | The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file. | |
| Modificada | Media (5.5) | 1.9% | — | Gnome Gdk-pixbufFedoraproject FedoraDebian Linux | 10/3/2017 | 17/6/2026 | The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (infinite loop) via a large TIFF file. | |
| Modificada | Alta (7.1) | 1.9% | — | Gnome Gdk-pixbufFedoraproject FedoraDebian Linux | 10/3/2017 | 17/6/2026 | Integer underflow in the load_resources function in io-icns.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (out-of-bounds read and program crash) via a crafted image entry size in an ICO file. | |
| Modificada | Media (5.5) | 2.0% | — | Gnome Gdk-pixbufFedoraproject FedoraDebian Linux | 10/3/2017 | 17/6/2026 | Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, which triggers an out-of-bounds read, related to compiler optimizations. | |
| Modificada | Alta (7.5) | 3.5% | — | Gnome Gdk-pixbufFedoraproject Fedora | 10/3/2017 | 17/6/2026 | gdk-pixbuf-thumbnailer.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to printing an error message. | |
| Modificada | Crítica (9.8) | 5.0% | — | Fedoraproject FedoraGnome Gtk-vnc | 28/2/2017 | 17/6/2026 | Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow. | |
| Modificada | Alta (7.8) | 2.2% | — | Fedoraproject FedoraGnome Gtk-vnc | 28/2/2017 | 17/6/2026 | gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile. | |
| Modificada | Media (5.5) | 1.4% | — | Gnome Librsvg | 3/2/2017 | 17/6/2026 | The rsvg_pattern_fix_fallback function in rsvg-paint_server.c in librsvg2 2.40.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted svg file. | |
| Modificada | Media (5.5) | 1.3% | — | Gnome Libgsf | 8/12/2016 | 17/6/2026 | An error within the "tar_directory_for_file()" function (gsf-infile-tar.c) in GNOME Structured File Library before 1.14.41 can be exploited to trigger a Null pointer dereference and subsequently cause a crash via a crafted TAR file. | |
| Modificada | Baja (3.7) | 0.87% | — | Gnome ShotwellRedhat Enterprise Linux | 25/10/2016 | 17/6/2026 | Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks. | |
| Modificada | Alta (7.5) | 3.9% | — | Canonical Ubuntu LinuxGnome Gdk-pixbufOpensuse LeapOpensuse | 3/10/2016 | 17/6/2026 | The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via crafted dimensions in an ICO file. | |
| Modificada | Alta (7.5) | 18% | 💥 Exploit | Fedoraproject FedoraOpensuse LeapOpensuseCanonical Ubuntu Linux+1 | 7/9/2016 | 17/6/2026 | Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup. | |
| Modificada | Alta (7.8) | 2.8% | — | Gnome Gdk-pixbufDebian Linux | 1/6/2016 | 17/6/2026 | Multiple integer overflows in the (1) pixops_composite_nearest, (2) pixops_composite_color_nearest, and (3) pixops_process functions in pixops/pixops.c in gdk-pixbuf before 2.33.1 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image, which… | |
| Modificada | Alta (7.5) | 2.4% | — | Gnome LibrsvgDebian LinuxOpensuse LeapOpensuse | 20/5/2016 | 17/6/2026 | The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via circular definitions in an SVG document. | |
| Modificada | Alta (7.5) | 2.4% | — | Debian LinuxGnome Librsvg | 20/5/2016 | 17/6/2026 | librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via cyclic references in an SVG document. | |
| Modificada | Alta (7.5) | 2.0% | — | Gnome Librsvg | 20/5/2016 | 17/6/2026 | The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via an odd number of elements in a coordinate pair in an SVG document. | |
| Modificada | Media (6.5) | 0.76% | — | Canonical Ubuntu LinuxXchatXchat GnomeHexchat Project Hexchat | 21/4/2016 | 17/6/2026 | The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Alta (7.2) | 0.41% | — | Fedoraproject FedoraGnome Display Manager | 24/11/2015 | 17/6/2026 | GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the Escape key. |