Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

432 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)2.8%—Gnome Evolution17/4/202017/6/2026
An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email message without showing a warning to the user, as demonstrated by an…
ModificadaBaja (3.9)0.77%—Gnome File-rollerDebian LinuxCanonical Ubuntu Linux13/4/202017/6/2026
fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
ModificadaAlta (7.8)2.1%💥 PoCGnome GthumbLinuxmint PIXDebian Linux16/3/202017/6/2026
A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.
ModificadaMedia (5.5)0.71%💥 ExploitGnome NetworkmanagerDebian Linux10/3/202016/6/2026
NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.
ModificadaCrítica (9.8)4.3%—Gnome GTKXchatXchat-wdk21/2/202016/6/2026
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 line from server containing characters outside of the Basic Multilingual Plane (BMP).
ModificadaAlta (7.5)1.9%—Gnome EvolutionGnome Evolution Data ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+16/2/202016/6/2026
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain…
ModificadaMedia (6.5)2.1%—Gnome LibrsvgOpensuse LeapFedoraproject FedoraDebian Linux+22/2/202017/6/2026
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.
ModificadaMedia (6.8)0.88%—Gnome NetworkmanagerOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server27/1/202016/6/2026
NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.
ModificadaMedia (5.9)2.2%—Gnome GlibFedoraproject Fedora9/1/202017/6/2026
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security…
ModificadaMedia (4.4)0.43%—Gnome NetworkmanagerDebian LinuxCanonical Ubuntu LinuxOpensuse26/12/201916/6/2026
In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.
ModificadaAlta (7.5)1.5%—Gnome KeyringDebian Linux20/12/201916/6/2026
gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function
ModificadaAlta (7.3)0.51%—Gnome OrcaDebian Linux11/12/201916/6/2026
Orca has arbitrary code execution due to insecure Python module load
ModificadaMedia (5.5)0.37%—Gnome DIAFedoraproject FedoraOpensuse Leap29/11/201917/6/2026
When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thumbnailer service, this output will usually be written to disk via the system's logging facility…
ModificadaMedia (5.5)0.91%—Gnome-font-viewer27/11/201917/6/2026
In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing a TTF font file that lacks a name section (due to a g_strconcat call that returns NULL).
ModificadaAlta (7.3)0.78%—Gnome Evolution-data-server325/11/201916/6/2026
evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could use this flaw to obtain login credentials of the victim.
ModificadaAlta (7.5)1.6%—Gnome-system-logFedoraproject Fedora25/11/201916/6/2026
gnome-system-log polkit policy allows arbitrary files on the system to be read
ModificadaCrítica (9.8)1.9%—Gnome Gdk-pixbufRedhat Enterprise LinuxDebian Linux12/11/201916/6/2026
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw
ModificadaBaja (2.4)0.55%—Gnome Display ManagerRedhat Enterprise LinuxDebian LinuxOpensuse Leap5/11/201917/6/2026
gdm3 3.14.2 and possibly later has an information leak before screen lock
ModificadaMedia (5.5)1.1%—Gnome EvinceDebian LinuxOpensuseRedhat Enterprise Linux1/11/201916/6/2026
evince is missing a check on number of pages which can lead to a segmentation fault
ModificadaCrítica (9.8)2.8%—Gnome LibsoupCanonical Ubuntu Linux6/10/201917/6/2026
libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.
ModificadaMedia (4.3)2.1%—Gnome File-rollerCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux21/9/201917/6/2026
An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.
ModificadaAlta (8.1)0.99%—Gnome Evolution-ewsRedhat Enterprise Linux1/8/201917/6/2026
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference.
ModificadaCrítica (9.8)6.3%—Gnome PangoOracle Sd-wan EdgeFedoraproject FedoraDebian Linux+919/7/201917/6/2026
Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass…
ModificadaAlta (7.8)2.1%—Gnome EvinceCanonical Ubuntu LinuxDebian LinuxOpensuse Leap15/7/201917/6/2026
Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs because of an incorrect integer overflow protection mechanism in tiff_document_render and…
ModificadaAlta (7.5)3.2%—Gnome Glib28/6/201917/6/2026
The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and files using g_file_replace_contents (kfsb->file, contents, length, NULL, FALSE, G_FILE_CREATE_REPLACE_DESTINATION, NULL, NULL, NULL). Consequently, it does not…
Orbitaley — Vulnerabilidades