Vulnerabilidades em Gnome

57 resultados
Análise Vexday

O Gnome apresenta um perfil de risco baixo com apenas 3 vulnerabilidades registradas na base, nenhuma sob ataque ativo ou classificada como crítica. O risco não é recente, sem publicações nos últimos 90 dias, e a fraqueza dominante (CWE-754: Improper Exception Handling) sugere problemas pontuais de tratamento de erros sem padrão de exploração ativa.

CVE-2026-82328MEDIUMGimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette countEPSS 0.3%CVE-2026-16615MEDIUMLibrest: weak random number generation in pkce implementationEPSS 0.3%CVE-2026-16768MEDIUMGdk-pixbuf: out-of-bounds read in ico parserEPSS 0.2%CVE-2026-80101MEDIUMGimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validationEPSS 0.2%CVE-2026-66757MEDIUMGimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi imagesEPSS 0.2%CVE-2026-84270MEDIUMGvfs: mtp: out-of-bounds read in do_read()EPSS 0.2%CVE-2026-77652HIGHDia: dia: heap buffer overflow in wpg colormap parser via out-of-bounds palette indexEPSS 0.2%CVE-2026-92248HIGHGimp: integer overflow when generating a thumbnail preview for a psd fileEPSS 0.2%CVE-2026-91839HIGHNetworkmanager-fortisslvpn: networkmanager-fortisslvpn: local privilege escalation to root via crlf injection in vpn profile credentialsEPSS 0.2%CVE-2026-77658HIGHDia: dia: stack buffer overflow in bus object via unvalidated handle count in project filesEPSS 0.2%CVE-2026-91841HIGHNetworkmanager-vpnc: networkmanager-vpnc: incomplete fix for cve-2018-10900 allows root privilege escalation via ca-file path newline injectionEPSS 0.2%CVE-2026-91840HIGHNetworkmanager-vpnc: networkmanager-vpnc: local privilege escalation to root via newline injection in vpn usernameEPSS 0.2%CVE-2026-44931MEDIUMmalcontent: Disk Space Exhaustion via Globally Accessible D-Bus APIEPSS 0.2%CVE-2026-91837HIGHNetworkmanager-iodine: networkmanager-iodine: local privilege escalation to root via nameserver option injectionEPSS 0.1%CVE-2026-97222MEDIUMGnumeric: gnumeric: heap use-after-free when opening a malformed workbookEPSS 0.1%CVE-2026-88924HIGHGvfs: gvfs-admin socket ownership race permits local rootEPSS 0.1%CVE-2026-91838HIGHNetworkmanager-sstp: networkmanager-sstp: local privilege escalation to root via shell injection in vpn profile fieldsEPSS 0.1%