Vulnerabilities in gnome

57 results
Vexday analysis

O GNOME apresenta um volume muito reduzido de vulnerabilidades conhecidas (1 CVE), com nenhuma evidência de exploração ativa no terreno. A fraqueza identificada (CWE-770 - alocação excessiva de recursos) é recente, publicada nos últimos 90 dias, e não atinge nível crítico, representando um risco moderado e monitorável.

CVE-2026-82328MEDIUMGimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette countEPSS 0.3%CVE-2026-16615MEDIUMLibrest: weak random number generation in pkce implementationEPSS 0.3%CVE-2026-16768MEDIUMGdk-pixbuf: out-of-bounds read in ico parserEPSS 0.2%CVE-2026-80101MEDIUMGimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validationEPSS 0.2%CVE-2026-66757MEDIUMGimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi imagesEPSS 0.2%CVE-2026-84270MEDIUMGvfs: mtp: out-of-bounds read in do_read()EPSS 0.2%CVE-2026-77652HIGHDia: dia: heap buffer overflow in wpg colormap parser via out-of-bounds palette indexEPSS 0.2%CVE-2026-92248HIGHGimp: integer overflow when generating a thumbnail preview for a psd fileEPSS 0.2%CVE-2026-91839HIGHNetworkmanager-fortisslvpn: networkmanager-fortisslvpn: local privilege escalation to root via crlf injection in vpn profile credentialsEPSS 0.2%CVE-2026-77658HIGHDia: dia: stack buffer overflow in bus object via unvalidated handle count in project filesEPSS 0.2%CVE-2026-91841HIGHNetworkmanager-vpnc: networkmanager-vpnc: incomplete fix for cve-2018-10900 allows root privilege escalation via ca-file path newline injectionEPSS 0.2%CVE-2026-91840HIGHNetworkmanager-vpnc: networkmanager-vpnc: local privilege escalation to root via newline injection in vpn usernameEPSS 0.2%CVE-2026-44931MEDIUMmalcontent: Disk Space Exhaustion via Globally Accessible D-Bus APIEPSS 0.2%CVE-2026-91837HIGHNetworkmanager-iodine: networkmanager-iodine: local privilege escalation to root via nameserver option injectionEPSS 0.1%CVE-2026-97222MEDIUMGnumeric: gnumeric: heap use-after-free when opening a malformed workbookEPSS 0.1%CVE-2026-88924HIGHGvfs: gvfs-admin socket ownership race permits local rootEPSS 0.1%CVE-2026-91838HIGHNetworkmanager-sstp: networkmanager-sstp: local privilege escalation to root via shell injection in vpn profile fieldsEPSS 0.1%