Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
432 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.9) | 0.36% | — | Gnome Nautilus-python | 28/1/2009 | 16/6/2026 | Untrusted search path vulnerability in the Python language bindings for Nautilus (nautilus-python) allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983). | |
| Modificada | Media (6.9) | 0.62% | — | Gnome LibpeasFedoraproject Fedora | 28/1/2009 | 16/6/2026 | Untrusted search path vulnerability in the Python module in gedit allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983). | |
| Modificada | Media (6.9) | 0.40% | — | Gnome EOG | 28/1/2009 | 16/6/2026 | Untrusted search path vulnerability in the Python interface in Eye of GNOME (eog) 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983). | |
| Modificada | Media (6.9) | 0.37% | — | Gnome Epiphany | 28/1/2009 | 16/6/2026 | Untrusted search path vulnerability in the Python interface in Epiphany 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983). | |
| Modificada | Media (6.8) | 9.1% | 💥 Exploit | Gnome Vinagre | 17/12/2008 | 16/6/2026 | Format string vulnerability in the vinagre_utils_show_error function (src/vinagre-utils.c) in Vinagre 0.5.x before 0.5.2 and 2.x before 2.24.2 might allow remote attackers to execute arbitrary code via format string specifiers in a crafted URI or VNC server response. | |
| Modificada | Media (6.9) | 0.34% | — | Mohammed Sameer Multi-gnome-terminal | 18/11/2008 | 16/6/2026 | mgt-helper in multi-gnome-terminal 1.6.2 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/*.debug or (2) /tmp/*.env temporary file. | |
| Modificada | Alta (10) | 19% | 💥 Exploit | Gnome YelpGnome | 18/8/2008 | 16/6/2026 | Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to execute arbitrary code via format string specifiers in an invalid URI on the command line, as demonstrated by use of yelp within (1) man or (2) ghelp URI handlers in… | |
| Modificada | Alta (9.3) | 5.7% | — | Gnome Evolution | 4/6/2008 | 16/6/2026 | Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar attachment, which is not properly handled during a reply in the calendar view (aka the Calendars window). | |
| Modificada | Alta (7.6) | 5.7% | — | Gnome Evolution | 4/6/2008 | 16/6/2026 | Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attachment. | |
| Modificada | Media (4.7) | 1.3% | — | Gnome Screensaver | 6/4/2008 | 16/6/2026 | gnome-screensaver before 2.22.1, when a remote authentication server is enabled, crashes upon an unlock attempt during a network outage, which allows physically proximate attackers to gain access to the locked session, a related issue to CVE-2007-1859. | |
| Modificada | Media (6.8) | 6.0% | — | Gnome Evolution | 6/3/2008 | 16/6/2026 | Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to execute arbitrary code via a crafted encrypted message, as demonstrated using the Version field. | |
| Modificada | Alta (9.3) | 5.0% | — | Gnome Gnumeric | 11/2/2008 | 16/6/2026 | The excel_read_HLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file containing XLS HLINK opcodes, possibly because of an integer signedness error that leads to an integer overflow. NOTE: some of… | |
| Modificada | Baja (2.1) | 0.37% | — | Gnome Screensaver | 17/12/2007 | 16/6/2026 | The notify feature in GNOME screensaver (gnome-screensaver) 2.20.0 might allow local users to read the clipboard contents and X selection data for a locked session by using ctrl-V. | |
| Modificada | Media (6.8) | 3.9% | — | Gnome Balsa | 12/12/2007 | 16/6/2026 | Stack-based buffer overflow in the ir_fetch_seq function in balsa before 2.3.20 might allow remote IMAP servers to execute arbitrary code via a long response to a FETCH command. | |
| Modificada | Media (6.8) | 3.4% | — | Ruby Gnome2 | 30/11/2007 | 16/6/2026 | Format string vulnerability in the mdiag_initialize function in gtk/src/rbgtkmessagedialog.c in Ruby-GNOME 2 (aka Ruby/Gnome2) 0.16.0, and SVN versions before 20071127, allows context-dependent attackers to execute arbitrary code via format string specifiers in the message parameter. | |
| Modificada | Media (6.2) | 0.36% | — | CompizGnome Screensaver | 29/10/2007 | 16/6/2026 | GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069. | |
| Modificada | Media (4.3) | 2.4% | — | Gnome-vfsMozilla FirefoxMozilla Seamonkey | 21/10/2007 | 16/6/2026 | Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2)… | |
| Modificada | Baja (1.5) | 0.33% | — | Gnome GDM | 7/8/2007 | 16/6/2026 | The GDM daemon in GNOME Display Manager (GDM) before 2.14.13, 2.16.x before 2.16.7, 2.18.x before 2.18.4, and 2.19.x before 2.19.5 does not properly handle NULL return values from the g_strsplit function, which allows local users to cause a denial of service (persistent daemon crash) via a crafted command to the… | |
| Modificada | Media (6.8) | 3.1% | — | Gnome Evolution | 19/6/2007 | 16/6/2026 | Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index. | |
| Modificada | Alta (9.3) | 3.5% | — | Gnome Ekiga | 10/3/2007 | 16/6/2026 | Format string vulnerability in Ekiga 2.0.3, and probably other versions, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2007-1006. | |
| Modificada | Media (5) | 5.2% | 💥 Exploit | Gnome Evolution | 6/3/2007 | 16/6/2026 | Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection. | |
| Modificada | Baja (2.1) | 0.93% | 💥 Exploit | Gnome GTK | 24/1/2007 | 16/6/2026 | The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image file. | |
| Modificada | Baja (1.9) | 0.43% | — | Gnome Gconf | 22/12/2006 | 16/6/2026 | The GConf daemon (gconfd) in GConf 2.14.0 creates temporary files under directories with names based on the username, even when GCONF_GLOBAL_LOCKS is not set, which allows local users to cause a denial of service by creating the directories ahead of time, which prevents other users from using Gnome. | |
| Modificada | Media (4.3) | 0.41% | — | Gnome GDM | 15/12/2006 | 16/6/2026 | Format string vulnerability in the host chooser window (gdmchooser) in GNOME Foundation Display Manager (gdm) allows local users to execute arbitrary code via format string specifiers in a hostname, which are used in an error dialog. | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Codeworks Gnomedia Subberz | 21/7/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in user-func.php in Codeworks Gnomedia SubberZ[Lite] allows remote attackers to execute arbitrary PHP code via a URL in the myadmindir parameter. NOTE: this issue has been disputed by a third party that claims that " the myadmindir variable is set before any GET variables are… |