vciy

CVEs we hold for Gnome

Records whose assigning authority named Gnome as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-92248Gimp: integer overflow when generating a thumbnail preview for a psd fileGNOME GIMP; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2026-88924Gvfs: gvfs-admin socket ownership race permits local rootGNOME gvfs; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2026-84270Gvfs: mtp: out-of-bounds read in do_read()GNOME gvfs; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2026-84269Gvfs: afp: heap-based buffer overflow in dsi read pathGNOME gvfs; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2026-84268Gvfs: sftp: heap-based buffer overflow in read_reply()GNOME gvfs; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2026-84267Gvfs: sftp: uninitialized heap disclosure in read_string()GNOME gvfs; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2026-82343Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handlingGNOME GIMP; Red Hat Enterprise Linux 6; Red Hat Enterprise…
CVE-2026-82330Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds checkGNOME GIMP; Red Hat Enterprise Linux 6; Red Hat Enterprise…
CVE-2026-82328Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette countGNOME GIMP; Red Hat Enterprise Linux 6; Red Hat Enterprise…
CVE-2026-82324Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=0GNOME GIMP; Red Hat Enterprise Linux 6; Red Hat Enterprise…
CVE-2026-80101Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validationGNOME GIMP; Red Hat Enterprise Linux 6; Red Hat Enterprise…
CVE-2026-79902Gimp: stack vla size underflow denial of service in seattleGNOME GIMP; Red Hat Enterprise Linux 6; Red Hat Enterprise…
CVE-2026-78475Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loaderGNOME GIMP; Red Hat Enterprise Linux 6; Red Hat Enterprise…
CVE-2026-78465Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bitGNOME GIMP; Red Hat Enterprise Linux 6; Red Hat Enterprise…
CVE-2026-77658Dia: dia: stack buffer overflow in bus object via unvalidated handle count in project filesGNOME Dia
CVE-2026-77652Dia: dia: heap buffer overflow in wpg colormap parser via out-of-bounds palette indexGNOME Dia
CVE-2026-66759Gimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted icns imagesGNOME GIMP; Red Hat Enterprise Linux 9; Red Hat Enterprise…
CVE-2026-66758Gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted fits imagesGNOME GIMP; Red Hat Enterprise Linux 8; Red Hat Enterprise…
CVE-2026-66757Gimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi imagesGNOME GIMP; Red Hat Enterprise Linux 6; Red Hat Enterprise…
CVE-2026-6653libxml2: Use after free in xmlParseInternalSubset via improper entity resolution handlingGNOME libxml2
CVE-2026-58016Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"GNOME GLib; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2026-58015Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receiveGNOME GLib; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2026-58014Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"GNOME GLib; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2026-58013Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"GNOME GLib; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2026-58012Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()GNOME GLib; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2026-58011Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetimeGNOME GLib; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2026-58010Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()GNOME GLib; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2026-44931malcontent: Disk Space Exhaustion via Globally Accessible D-Bus APIgnome malcontent
CVE-2026-2604Evolution-data-server: evolution data server: arbitrary file deletion via inconsistent uri handlingGNOME Evolution Data Server; Red Hat Enterprise Linux 10…
CVE-2026-18487Epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host()GNOME Epiphany
CVE-2026-18358Gnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing connection throttling allows unauthenticated…gnome-remote-desktop; Red Hat Enterprise Linux 10…
CVE-2026-16768Gdk-pixbuf: out-of-bounds read in ico parserGNOME gdk-pixbuf; Red Hat Enterprise Linux 10…
CVE-2026-16615Librest: weak random number generation in pkce implementationGNOME librest; Red Hat Enterprise Linux 10…
CVE-2025-7425Libxslt: libxml2: heap use-after-free in libxslt caused by atype corruption in xmlattrptrGNOME libxml2; Red Hat Enterprise Linux 10…
CVE-2025-7424Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodesGNOME libxslt; Red Hat Enterprise Linux 10…
CVE-2025-49795Libxml: null pointer dereference leads to denial of service (dos)GNOME libxml2; Red Hat Enterprise Linux 10…
CVE-2025-14512Glib: integer overflow in glib gio attribute escaping causes heap buffer overflowGNOME glib; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2025-14087Glib: glib: buffer underflow in gvariant parser leads to heap corruptionGNOME glib; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2025-12105Libsoup: heap use-after-free in libsoup message queue handling during http/2 read completionGNOME libsoup; Red Hat Enterprise Linux 10…
CVE-2024-52531no title heldGNOME libsoup
CVE-2024-42415no title heldGNOME Project G Structured File Library (libgsf)
CVE-2024-36474no title heldGNOME Project G Structured File Library (libgsf)
CVE-2021-42522no title heldn/a GNOME anjuta
CVE-2021-3982no title heldn/a gnome-shell
CVE-2021-20315no title heldn/a gnome-shell
CVE-2020-37011Gnome Fonts Viewer 3.34.0 Heap CorruptionGNOME Fonts Viewer
CVE-2020-16125gdm3 would start gnome-initial-setup if it cannot contact accountserviceGnome GDM3
CVE-2020-14391no title heldn/a gnome-settings-daemon
CVE-2019-25085GNOME gvdb gvdb-builder.c gvdb_table_write_contents_async use after freeGNOME gvdb
CVE-2019-1010238no title heldGnome Pango
CVE-2017-2885no title heldGNOME libsoup
CVE-2017-2870no title heldGNOME Gdk-Pixbuf
CVE-2017-2862no title heldGNOME Gdk-Pixbuf
CVE-2017-12164no title heldGNOME gdm
CVE-2013-4166no title heldGNOME Evolution Data Server
CVE-2012-6111no title heldgnome-keyring
CVE-2012-5535no title heldgnome-system-log
CVE-2012-1096no title heldGNOME NetworkManager
CVE-2011-1830Ekiga attempts to dlopen /tmp/ekiga_test.soGnome Ekiga

59 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.