Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
432 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 1.8% | — | Gnome Libsocialweb | 22/10/2012 | 16/6/2026 | (1) services/twitter/twitter-contact-view.c and (2) services/twitter/twitter-item-view.c in libsocialweb before 0.25.20 automatically connect to Twitter when no Twitter account is set, which might allow remote attackers to obtain sensitive information via a man-in-the-middle (MITM) attack. | |
| Modificada | Media (6.8) | 1.3% | — | Gnome-shell | 1/10/2012 | 16/6/2026 | The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a crafted web page. | |
| Modificada | Media (6.8) | 4.4% | — | Gnome Librsvg | 5/9/2012 | 16/6/2026 | librsvg before 2.34.1 uses the node name to identify the type of node, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference) and possibly execute arbitrary code via a SVG file with a node with the element name starting with "fe," which is misidentified as a… | |
| Modificada | Baja (3.3) | 0.31% | — | Gnome At-spi2-atk | 31/8/2012 | 16/6/2026 | The register_application function in atk-adaptor/bridge.c in GNOME at-spi2-atk 2.5.2 does not seed the random number generator and generates predictable temporary file names, which makes it easier for local users to create or truncate files via a symlink attack on a temporary socket file in /tmp/at-spi2. | |
| Modificada | Media (5.1) | 1.9% | — | Gnome Libgdata | 26/8/2012 | 16/6/2026 | libgdata before 0.10.2 and 0.11.x before 0.11.1 does not validate SSL certificates, which allows remote attackers to obtain user names and passwords via a man-in-the-middle (MITM) attack with a spoofed certificate. | |
| Modificada | Media (5) | 1.6% | — | Gnome Libsoup | 20/8/2012 | 16/6/2026 | libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection. | |
| Modificada | Media (5) | 4.1% | — | Gnome Gdk-pixbuf | 13/8/2012 | 16/6/2026 | Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in gdk-pixbuf before 2.26.1 allow remote attackers to cause a denial of service (application crash) via a negative (1) height or (2) width in an XBM file, which triggers a heap-based buffer overflow. | |
| Modificada | Baja (3.3) | 0.34% | — | Gnome Screensaver | 7/8/2012 | 16/6/2026 | gnome-screensaver 3.4.x before 3.4.4 and 3.5.x before 3.5.4, when multiple screens are used, only locks the screen with the active focus, which allows physically proximate attackers to bypass screen locking and access an unattended workstation. | |
| Modificada | Baja (3.6) | 0.56% | — | Gnome Rhythmbox | 17/7/2012 | 16/6/2026 | (1) AlbumTab.py, (2) ArtistTab.py, (3) LinksTab.py, and (4) LyricsTab.py in the Context module in GNOME Rhythmbox 0.13.3 and earlier allows local users to execute arbitrary code via a symlink attack on a temporary HTML template file in the /tmp/context directory. | |
| Modificada | Media (4.3) | 3.1% | — | Gnome Gdk-pixbuf | 3/7/2012 | 16/6/2026 | The gdk_pixbuf__gif_image_load function in gdk-pixbuf/io-gif.c in gdk-pixbuf before 2.23.5 does not properly handle certain return values, which allows remote attackers to cause a denial of service (memory consumption) via a crafted GIF image file. | |
| Modificada | Alta (9.3) | 7.3% | — | Gnome PangoQTCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+4 | 16/6/2012 | 16/6/2026 | Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file. | |
| Modificada | Baja (2.1) | 0.35% | — | Gnome Update-manager-coreCanonical Ubuntu Linux | 7/6/2012 | 16/6/2026 | DistUpgrade/DistUpgradeMain.py in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uses weak permissions for (1) apt-clone_system_state.tar.gz and (2) system_state.tar.gz, which allows local users to obtain repository credentials. | |
| Modificada | Alta (7.5) | 2.0% | — | Gnome Glib | 14/1/2012 | 16/6/2026 | GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this… | |
| Modificada | Media (6.9) | 0.46% | — | Gnome Ifcfg-rh Plug-in | 4/11/2011 | 16/6/2026 | Incomplete blacklist vulnerability in the svEscape function in settings/plugins/ifcfg-rh/shvar.c in the ifcfg-rh plug-in for GNOME NetworkManager 0.9.1, 0.9.0, 0.8.1, and possibly other versions, when PolicyKit is configured to allow users to create new connections, allows local users to execute arbitrary commands via… | |
| Modificada | Media (4.3) | 0.90% | — | Gnome Empathy | 23/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted alias (aka nickname) in a /me event, a different vulnerability than… | |
| Modificada | Media (4.3) | 2.0% | — | Gnome Empathy | 23/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted alias (aka nickname). | |
| Modificada | Alta (9.3) | 2.0% | — | Gnome GTK | 6/9/2011 | 16/6/2026 | Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan horse uxtheme.dll file in the current working directory, a different vulnerability than CVE-2010-4831. | |
| Modificada | Media (6.9) | 0.39% | — | Gnome GTK | 6/9/2011 | 16/6/2026 | Untrusted search path vulnerability in gdk/win32/gdkinput-win32.c in GTK+ before 2.21.8 allows local users to gain privileges via a Trojan horse Wintab32.dll file in the current working directory. | |
| Modificada | Baja (2.1) | 0.32% | — | Gnome Networkmanager | 2/9/2011 | 16/6/2026 | GNOME NetworkManager before 0.8.6 does not properly enforce the auth_admin element in PolicyKit, which allows local users to bypass intended wireless network sharing restrictions via unspecified vectors. | |
| Modificada | Media (5) | 1.9% | — | Gnome Libsoup | 31/8/2011 | 16/6/2026 | Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI. | |
| Modificada | Alta (7.2) | 0.36% | — | Hongli LAI Libgnomesu | 7/7/2011 | 16/6/2026 | gnomesu-pam-backend in libgnomesu 1.0.0 prints an error message but proceeds with the non-error code path upon failure of the setgid or setuid function, which allows local users to gain privileges by leveraging access to two unprivileged user accounts, and running many processes under one of these accounts. | |
| Modificada | Baja (2.1) | 0.21% | — | Gnome NetworkmanagerFedoraproject Fedora | 14/6/2011 | 16/6/2026 | The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0.8.999-3.git20110526 in Fedora 15 creates a log entry containing a certificate password, which allows local users to obtain sensitive information by reading a log file. | |
| Modificada | Alta (7.2) | 0.43% | — | Gnome GDM | 14/6/2011 | 16/6/2026 | GNOME Display Manager (gdm) before 2.32.2, when glib 2.28 is used, enables execution of a web browser with the uid of the gdm account, which allows local users to gain privileges via vectors involving the x-scheme-handler/http MIME type. | |
| Modificada | Media (6.9) | 0.38% | — | Gnome GDM | 31/3/2011 | 16/6/2026 | GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/. | |
| Modificada | Media (6.8) | 3.3% | — | Gnome PangoMozilla Firefox | 7/3/2011 | 16/6/2026 | The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via crafted… |