Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

432 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)2.3%—Gnome Gdk-pixbufFedoraproject Fedora28/5/202117/6/2026
A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victim system. The highest threat from this vulnerability is to data…
ModificadaAlta (7.8)1.6%—Gnome EvolutionYtnef Project Ytnef26/5/202116/6/2026
Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding…
ModificadaMedia (5.5)0.26%—Gnome NetworkmanagerRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora26/5/202117/6/2026
A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.
ModificadaAlta (7.5)1.4%—Gnome Libgrss25/5/202117/6/2026
libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.
ModificadaAlta (8.1)1.1%—Gnome Gupnp24/5/202117/6/2026
An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be…
ModificadaBaja (3.9)0.61%—Gnome File-rollerFedoraproject Fedora7/4/202117/6/2026
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
ModificadaMedia (5.5)0.53%—Gnome-autoarFedoraproject Fedora17/3/202117/6/2026
autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for…
ModificadaMedia (5.3)2.6%—Gnome GlibBroadcom Brocade Fabric Operating System FirmwareDebian LinuxFedoraproject Fedora11/3/202117/6/2026
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is…
ModificadaAlta (7.5)3.0%—Gnome GlibFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+315/2/202117/6/2026
An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption.
ModificadaAlta (7.5)4.1%—Gnome GlibFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+315/2/202117/6/2026
An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing unintended length truncation.
ModificadaMedia (5.5)0.32%—Gnome Control Center8/2/202117/6/2026
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password.…
ModificadaMedia (5.5)0.64%—Gnome-autoarFedoraproject Fedora5/2/202117/6/2026
autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
ModificadaBaja (3.3)0.35%—Gnome Evolution1/2/202117/6/2026
GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this…
ModificadaMedia (6.4)0.23%—Gnome Display Manager28/12/202017/6/2026
A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to…
AnalizadaMedia (5.5)1.5%—Gnome Gdk-pixbufCanonical Ubuntu LinuxFedoraproject Fedora26/12/202017/6/2026
GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next execution in the loop will assign self->code_table[11].extends to c, which will give the…
ModificadaAlta (7.8)0.57%—Gnome Glib14/12/202017/6/2026
GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's position is "Realistically this is not a security issue. The standard pattern is for callers to provide a static list of option entries in a fixed number of calls to…
ModificadaMedia (6.8)1.1%💥 PoCGnome Display Manager10/11/202017/6/2026
gdm3 versions before 3.36.2 or 3.38.2 would start gnome-initial-setup if gdm3 can't contact the accountservice service via dbus in a timely manner; on Ubuntu (and potentially derivatives) this could be be chained with an additional issue that could allow a local user to create a new privileged account.
ModificadaMedia (5.9)0.92%—Gnome GearyFedoraproject Fedora26/8/202017/6/2026
GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system-provided PKCS#11 store. This allows a meddler in the middle to present a different invalid…
ModificadaMedia (4.3)0.55%—Gnome-shellCanonical Ubuntu LinuxDebian LinuxOpensuse Leap11/8/202017/6/2026
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment…
ModificadaAlta (7.5)2.1%—Gnome BalsaOpensuse Backports SLEOpensuse Leap29/7/202017/6/2026
In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c.
ModificadaMedia (5.9)2.1%—Gnome Evolution-data-serverDebian Linux29/7/202017/6/2026
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.
ModificadaMedia (5.9)2.8%—Gnome Evolution-data-serverDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux17/7/202017/6/2026
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."
ModificadaMedia (4.3)0.99%—Gnome NetworkmanagerFedoraproject Fedora8/6/202017/6/2026
It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made insecurely.
ModificadaMedia (6.5)2.0%—Gnome BalsaGnome Glib-networkingCanonical Ubuntu LinuxFedoraproject Fedora+228/5/202017/6/2026
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications…
ModificadaAlta (7.1)2.3%—Gnome Libcroco12/5/202017/6/2026
libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.
Orbitaley — Vulnerabilidades