Show filters
309 Total Results
Displaying 101-110 of 309
Sort by:
Attacker Value
Unknown

CVE-2018-15587

Disclosure Date: February 11, 2019 (last updated November 27, 2024)
GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment.
0
Attacker Value
Unknown

CVE-2019-3825

Disclosure Date: February 06, 2019 (last updated November 27, 2024)
A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by selecting the timed login user and waiting for the timer to expire, at which time they would gain access to the logged-in user's session.
0
Attacker Value
Unknown

CVE-2019-3820

Disclosure Date: February 06, 2019 (last updated November 27, 2024)
It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.
Attacker Value
Unknown

CVE-2019-6251

Disclosure Date: January 14, 2019 (last updated November 08, 2023)
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.
0
Attacker Value
Unknown

CVE-2018-19358

Disclosure Date: November 18, 2018 (last updated November 08, 2023)
GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that this occurs because available D-Bus protection mechanisms (involving the busconfig and policy XML elements) are not used. NOTE: the vendor disputes this because, according to the security model, untrusted applications must not be allowed to access the user's session bus socket.
0
Attacker Value
Unknown

CVE-2008-7320

Disclosure Date: November 18, 2018 (last updated November 08, 2023)
GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow dialog at an unattended workstation, if the keyring is unlocked. NOTE: this is disputed by a software maintainer because the behavior represents a design decision
0
Attacker Value
Unknown

CVE-2018-18718

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the add_themes_from_dir method in dlg-contact-sheet.c because of two successive calls of g_free, each of which frees the same buffer.
0
Attacker Value
Unknown

CVE-2018-16428

Disclosure Date: September 04, 2018 (last updated November 27, 2024)
In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.
0
Attacker Value
Unknown

CVE-2018-16429

Disclosure Date: September 04, 2018 (last updated November 08, 2023)
GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().
0
Attacker Value
Unknown

CVE-2018-15120

Disclosure Date: August 24, 2018 (last updated November 27, 2024)
libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.