Vulnerabilidades em GNOME
51 resultadosAnálise Vexday
O GNOME apresenta 26 CVEs registradas, com 11 publicadas nos últimos 90 dias, indicando atividade contínua de descoberta de vulnerabilidades. Nenhuma vulnerabilidade está sob exploração ativa (KEV), e apenas 1 é crítica, sugerindo risco moderado no momento. A fraqueza dominante (CWE-416 - use-after-free) representa o principal vetor técnico, típico de problemas de segurança em aplicações desktop com ciclo de vida de objetos complexo.
CVE-2026-58011MEDIUMGlib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetimeEPSS 0.5%CVE-2020-37011HIGHGnome Fonts Viewer 3.34.0 Heap CorruptionEPSS 0.4%CVE-2025-12105HIGHLibsoup: heap use-after-free in libsoup message queue handling during http/2 read completionEPSS 0.4%CVE-2026-58014HIGHGlib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"EPSS 0.4%CVE-2017-12164MEDIUMA flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled EPSS 0.4%CVE-2025-7425HIGHLibxslt: libxml2: heap use-after-free in libxslt caused by atype corruption in xmlattrptrEPSS 0.4%CVE-2026-6653HIGHlibxml2: Use after free in xmlParseInternalSubset via improper entity resolution handlingEPSS 0.4%CVE-2026-84268HIGHGvfs: sftp: heap-based buffer overflow in read_reply()EPSS 0.3%CVE-2026-18487MEDIUMEpiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host()EPSS 0.3%CVE-2026-66758HIGHGimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted fits imagesEPSS 0.3%CVE-2026-16615MEDIUMLibrest: weak random number generation in pkce implementationEPSS 0.3%CVE-2026-66759HIGHGimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted icns imagesEPSS 0.3%CVE-2026-84269MEDIUMGvfs: afp: heap-based buffer overflow in dsi read pathEPSS 0.2%CVE-2026-16768MEDIUMGdk-pixbuf: out-of-bounds read in ico parserEPSS 0.2%CVE-2026-78465HIGHGimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bitEPSS 0.2%CVE-2026-66757MEDIUMGimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi imagesEPSS 0.2%CVE-2026-80101MEDIUMGimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validationEPSS 0.2%CVE-2026-84267MEDIUMGvfs: sftp: uninitialized heap disclosure in read_string()EPSS 0.2%CVE-2026-79902MEDIUMGimp: stack vla size underflow denial of service in seattleEPSS 0.2%CVE-2026-2604MEDIUMEvolution-data-server: evolution data server: arbitrary file deletion via inconsistent uri handlingEPSS 0.2%