Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
432 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 2.8% | — | Gnome Evolution | 17/4/2020 | 17/6/2026 | An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email message without showing a warning to the user, as demonstrated by an… | |
| Modificada | Baja (3.9) | 0.77% | — | Gnome File-rollerDebian LinuxCanonical Ubuntu Linux | 13/4/2020 | 17/6/2026 | fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location. | |
| Modificada | Alta (7.8) | 2.1% | 💥 PoC | Gnome GthumbLinuxmint PIXDebian Linux | 16/3/2020 | 17/6/2026 | A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file. | |
| Modificada | Media (5.5) | 0.71% | 💥 Exploit | Gnome NetworkmanagerDebian Linux | 10/3/2020 | 16/6/2026 | NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection. | |
| Modificada | Crítica (9.8) | 4.3% | — | Gnome GTKXchatXchat-wdk | 21/2/2020 | 16/6/2026 | Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 line from server containing characters outside of the Basic Multilingual Plane (BMP). | |
| Modificada | Alta (7.5) | 1.9% | — | Gnome EvolutionGnome Evolution Data ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 6/2/2020 | 16/6/2026 | The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain… | |
| Modificada | Media (6.5) | 2.1% | — | Gnome LibrsvgOpensuse LeapFedoraproject FedoraDebian Linux+2 | 2/2/2020 | 17/6/2026 | In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially. | |
| Modificada | Media (6.8) | 0.88% | — | Gnome NetworkmanagerOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server | 27/1/2020 | 16/6/2026 | NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used. | |
| Modificada | Media (5.9) | 2.2% | — | Gnome GlibFedoraproject Fedora | 9/1/2020 | 17/6/2026 | GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security… | |
| Modificada | Media (4.4) | 0.43% | — | Gnome NetworkmanagerDebian LinuxCanonical Ubuntu LinuxOpensuse | 26/12/2019 | 16/6/2026 | In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network. | |
| Modificada | Alta (7.5) | 1.5% | — | Gnome KeyringDebian Linux | 20/12/2019 | 16/6/2026 | gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function | |
| Modificada | Alta (7.3) | 0.51% | — | Gnome OrcaDebian Linux | 11/12/2019 | 16/6/2026 | Orca has arbitrary code execution due to insecure Python module load | |
| Modificada | Media (5.5) | 0.37% | — | Gnome DIAFedoraproject FedoraOpensuse Leap | 29/11/2019 | 17/6/2026 | When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thumbnailer service, this output will usually be written to disk via the system's logging facility… | |
| Modificada | Media (5.5) | 0.91% | — | Gnome-font-viewer | 27/11/2019 | 17/6/2026 | In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing a TTF font file that lacks a name section (due to a g_strconcat call that returns NULL). | |
| Modificada | Alta (7.3) | 0.78% | — | Gnome Evolution-data-server3 | 25/11/2019 | 16/6/2026 | evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could use this flaw to obtain login credentials of the victim. | |
| Modificada | Alta (7.5) | 1.6% | — | Gnome-system-logFedoraproject Fedora | 25/11/2019 | 16/6/2026 | gnome-system-log polkit policy allows arbitrary files on the system to be read | |
| Modificada | Crítica (9.8) | 1.9% | — | Gnome Gdk-pixbufRedhat Enterprise LinuxDebian Linux | 12/11/2019 | 16/6/2026 | gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw | |
| Modificada | Baja (2.4) | 0.55% | — | Gnome Display ManagerRedhat Enterprise LinuxDebian LinuxOpensuse Leap | 5/11/2019 | 17/6/2026 | gdm3 3.14.2 and possibly later has an information leak before screen lock | |
| Modificada | Media (5.5) | 1.1% | — | Gnome EvinceDebian LinuxOpensuseRedhat Enterprise Linux | 1/11/2019 | 16/6/2026 | evince is missing a check on number of pages which can lead to a segmentation fault | |
| Modificada | Crítica (9.8) | 2.8% | — | Gnome LibsoupCanonical Ubuntu Linux | 6/10/2019 | 17/6/2026 | libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy. | |
| Modificada | Media (4.3) | 2.1% | — | Gnome File-rollerCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux | 21/9/2019 | 17/6/2026 | An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction. | |
| Modificada | Alta (8.1) | 0.99% | — | Gnome Evolution-ewsRedhat Enterprise Linux | 1/8/2019 | 17/6/2026 | It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference. | |
| Modificada | Crítica (9.8) | 6.3% | — | Gnome PangoOracle Sd-wan EdgeFedoraproject FedoraDebian Linux+9 | 19/7/2019 | 17/6/2026 | Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass… | |
| Modificada | Alta (7.8) | 2.1% | — | Gnome EvinceCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 15/7/2019 | 17/6/2026 | Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs because of an incorrect integer overflow protection mechanism in tiff_document_render and… | |
| Modificada | Alta (7.5) | 3.2% | — | Gnome Glib | 28/6/2019 | 17/6/2026 | The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and files using g_file_replace_contents (kfsb->file, contents, length, NULL, FALSE, G_FILE_CREATE_REPLACE_DESTINATION, NULL, NULL, NULL). Consequently, it does not… |