Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

432 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.39%—Gnome Gvfs11/6/201917/6/2026
daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a…
ModificadaCrítica (9.8)2.6%—Gnome GlibDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUS+529/5/201917/6/2026
file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.
ModificadaMedia (5.7)1.8%—Gnome GvfsCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap29/5/201917/6/2026
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with G_FILE_COPY_ALL_METADATA) operations from admin:// to file:// URIs, because root privileges are unavailable.
ModificadaAlta (8.1)1.8%—Gnome Gvfs29/5/201917/6/2026
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c has race conditions because the admin backend doesn't implement query_info_on_read/write.
ModificadaAlta (7.3)1.8%—Gnome GvfsCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap29/5/201917/6/2026
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used.
ModificadaCrítica (9)2.0%—Gnome-desktop22/4/201917/6/2026
An issue was discovered in GNOME gnome-desktop 3.26, 3.28, and 3.30 prior to 3.30.2.2, and 3.32 prior to 3.32.1.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal,…
ModificadaMedia (5.5)1.4%—Gnome EvinceCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux+522/4/201917/6/2026
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.
ModificadaAlta (7.8)0.35%—Gnome Nautilus22/4/201917/6/2026
An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal, allowing an attacker to escape…
ModificadaAlta (7)0.36%—Gnome Gvfs25/3/201917/6/2026
An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users…
ModificadaMedia (6.5)2.3%—Gnome Glib8/3/201917/6/2026
gio/gsocketclient.c in GNOME GLib 2.59.2 does not ensure that a parent GTask remains alive during the execution of a connection-attempting enumeration, which allows remote attackers to cause a denial of service (g_socket_client_connected_callback mishandling and application crash) via a crafted web site, as…
ModificadaAlta (7.8)1.1%—Gnome Gdk-pixbufGnome Nautilus7/3/201917/6/2026
GdkPixBuf (aka gdk-pixbuf), possibly 2.32.2, as used by GNOME Nautilus 3.14.3 on Ubuntu 16.04, allows attackers to cause a denial of service (stack corruption) or possibly have unspecified other impact via a crafted file folder.
ModificadaAlta (7.8)1.5%—Gnome KeyringCanonical Ubuntu LinuxOracle ZFS Storage Appliance KIT12/2/201917/6/2026
In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.
ModificadaMedia (6.5)2.4%—Gnome EvolutionDebian Linux11/2/201917/6/2026
GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment.
ModificadaMedia (6.4)0.50%—Gnome Display ManagerCanonical Ubuntu LinuxRedhat Enterprise Linux6/2/201917/6/2026
A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by selecting the timed login user and waiting for the timer to expire, at which time they would gain access to the logged-in user's session.
ModificadaMedia (4.3)0.50%—Gnome-shellOpensuse LeapCanonical Ubuntu Linux6/2/201917/6/2026
It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.
ModificadaAlta (8.1)4.3%—Gnome EpiphanyWebkitgtkWpewebkit WPE WebkitFedoraproject Fedora+214/1/201917/6/2026
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.
ModificadaAlta (7.8)0.56%—Gnome-keyring18/11/201817/6/2026
GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that this occurs because available D-Bus protection mechanisms (involving the busconfig and policy XML…
ModificadaMedia (6.8)0.45%—Gnome Seahorse18/11/201816/6/2026
GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow dialog at an unattended workstation, if the keyring is unlocked. NOTE: this is disputed by a software maintainer because the behavior represents a design decision
ModificadaAlta (7.8)0.41%—Gnome GthumbDebian Linux29/10/201817/6/2026
An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the add_themes_from_dir method in dlg-contact-sheet.c because of two successive calls of g_free, each of which frees the same buffer.
ModificadaAlta (7.5)3.5%—Gnome GlibCanonical Ubuntu Linux4/9/201817/6/2026
GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().
ModificadaCrítica (9.8)4.7%—Gnome GlibCanonical Ubuntu Linux4/9/201817/6/2026
In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.
ModificadaMedia (6.5)11%💥 ExploitGnome PangoCanonical Ubuntu Linux24/8/201817/6/2026
libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.
ModificadaAlta (7.8)0.53%—Gnome Display Manager14/8/201817/6/2026
The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code execution.
ModificadaMedia (6.4)0.39%—Gnome Display Manager26/7/201817/6/2026
A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as another user' to unlock their screen.
ModificadaAlta (7.8)3.9%💥 ExploitGnome Network Manager VpncDebian Linux26/7/201817/6/2026
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.
Orbitaley — Vulnerabilidades