Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
432 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.6) | 19% | 💥 Exploit | Gnome PangoPango | 24/1/2011 | 16/6/2026 | Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted… | |
| Modificada | Media (6.9) | 0.41% | — | Gnome Tomboy | 6/11/2010 | 16/6/2026 | The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: vector 1 exists because of an incorrect fix for CVE-2005-4790.2. | |
| Modificada | Media (6.9) | 0.31% | — | Gnome-shell | 6/11/2010 | 16/6/2026 | gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | |
| Modificada | Media (6.9) | 0.40% | — | Pedro Castro Gnome-subtitles | 20/10/2010 | 16/6/2026 | gnome-subtitles 1.0 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | |
| Modificada | Media (5.8) | 1.0% | — | Gnome Epiphany | 14/10/2010 | 16/6/2026 | Epiphany 2.28 and 2.29, when WebKit and LibSoup are used, unconditionally displays a closed-lock icon for any URL beginning with the https: substring, without any warning to the user, which allows man-in-the-middle attackers to spoof arbitrary https web sites via a crafted X.509 server certificate. | |
| Modificada | Alta (7.2) | 0.33% | — | Gnome Power Manager | 7/9/2010 | 16/6/2026 | gnome-power-manager 2.27.92 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to… | |
| Modificada | Alta (7.2) | 0.37% | — | Gnome Power Manager | 7/9/2010 | 16/6/2026 | gnome-power-manager 2.14.0 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to… | |
| Modificada | Media (6.2) | 0.30% | — | Gnome GTKGnome Screensaver | 19/3/2010 | 16/6/2026 | gdk/gdkwindow.c in GTK+ before 2.18.5, as used in gnome-screensaver before 2.28.1, performs implicit paints on windows of type GDK_WINDOW_FOREIGN, which triggers an X error in certain circumstances and consequently allows physically proximate attackers to bypass screen locking and access an unattended workstation by… | |
| Modificada | Media (4.3) | 2.4% | — | Gnome Pango | 18/3/2010 | 16/6/2026 | Array index error in the hb_ot_layout_build_glyph_classes function in pango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted font file, related to building a synthetic Glyph Definition (aka GDEF) table by using this font's… | |
| Modificada | Media (4) | 0.36% | — | Gnome Screensaver | 24/2/2010 | 16/6/2026 | gnome-screensaver 2.28.x before 2.28.3 does not properly synchronize the state of screen locking and the unlock dialog in situations involving a change to the number of monitors, which allows physically proximate attackers to bypass screen locking and access an unattended workstation by connecting and disconnecting… | |
| Modificada | Media (5.6) | 0.30% | — | Gnome Screensaver | 24/2/2010 | 16/6/2026 | gnome-screensaver 2.14.3, 2.22.2, 2.27.x, 2.28.0, and 2.28.3, when the X configuration enables the extend screen option, allows physically proximate attackers to bypass screen locking, access an unattended workstation, and view half of the GNOME desktop by attaching an external monitor. | |
| Modificada | Alta (7.2) | 0.34% | — | Gnome Screensaver | 11/2/2010 | 16/6/2026 | gnome-screensaver 2.26.1 relies on the gnome-session D-Bus interface to determine session idle time, even when an Xfce desktop such as Xubuntu or Mythbuntu is used, which allows physically proximate attackers to access an unattended workstation on which screen locking had been intended. | |
| Modificada | Alta (7.2) | 0.37% | — | Gnome Screensaver | 11/2/2010 | 16/6/2026 | gnome-screensaver 2.28.0 does not resume adherence to its activation settings after an inhibiting application becomes unavailable on the session bus, which allows physically proximate attackers to access an unattended workstation on which screen locking had been intended. | |
| Modificada | Alta (7.2) | 0.42% | — | Gnome Screensaver | 11/2/2010 | 16/6/2026 | gnome-screensaver before 2.28.2 allows physically proximate attackers to bypass screen locking and access an unattended workstation by moving the mouse position to an external monitor and then disconnecting that monitor. | |
| Modificada | Alta (7.5) | 3.3% | — | Gnome Gmime | 8/2/2010 | 16/6/2026 | Buffer overflow in the GMIME_UUENCODE_LEN macro in gmime/gmime-encodings.h in GMime before 2.4.15 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via input data for a uuencode operation. | |
| Modificada | Baja (2.1) | 0.38% | — | Gnome Networkmanager | 23/12/2009 | 16/6/2026 | nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to discover the password for the WiFi network. | |
| Modificada | Media (6.8) | 1.9% | — | Gnome Networkmanager | 23/12/2009 | 16/6/2026 | NetworkManager (NM) 0.7.2 does not ensure that the configured Certification Authority (CA) certificate file for a (1) WPA Enterprise or (2) 802.1x network remains present upon a connection attempt, which might allow remote attackers to obtain sensitive information or cause a denial of service (connectivity disruption)… | |
| Modificada | Alta (9.3) | 3.8% | — | Gnome GpdfKdegraphicsKDE KpdfXpdf | 21/12/2009 | 16/6/2026 | The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font… | |
| Modificada | Alta (7.8) | 0.36% | — | Gnome GlibOpensuseSuse Linux Enterprise Server | 22/9/2009 | 16/6/2026 | The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory. | |
| Modificada | Media (4.3) | 3.1% | 💥 Exploit | Gnome Rhythmbox | 8/9/2009 | 16/6/2026 | GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlist (.pls) file with a long Title field, possibly related to the g_hash_table_lookup function in b-playlist-manager.c. | |
| Modificada | Media (6.8) | 1.8% | — | Gnome GDM | 4/9/2009 | 16/6/2026 | The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions via XDMCP connections, a different vulnerability than CVE-2007-5079. | |
| Modificada | Baja (2.1) | 0.44% | — | Gnome Evolution | 14/5/2009 | 16/6/2026 | The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to local mail, which allows local users to obtain sensitive information by reading these files. | |
| Modificada | Media (5.8) | 2.3% | — | Gnome Evolution-data-server | 14/3/2009 | 16/6/2026 | The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier, and 2.25.92 and earlier 2.25.x versions, does not validate whether a certain length value is consistent with the amount of data in a… | |
| Modificada | Media (4.6) | 0.49% | — | Gnome Glib | 14/3/2009 | 16/6/2026 | Multiple integer overflows in glib/gbase64.c in GLib before 2.20 allow context-dependent attackers to execute arbitrary code via a long string that is converted either (1) from or (2) to a base64 representation. | |
| Modificada | Media (6.9) | 0.39% | — | Gnome Gnumeric | 28/1/2009 | 16/6/2026 | Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983). |