Show filters
309 Total Results
Displaying 31-40 of 309
Sort by:
Attacker Value
Unknown

CVE-2021-45086

Disclosure Date: December 16, 2021 (last updated October 07, 2023)
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.
Attacker Value
Unknown

CVE-2021-45085

Disclosure Date: December 16, 2021 (last updated October 07, 2023)
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.
Attacker Value
Unknown

CVE-2021-39365

Disclosure Date: August 22, 2021 (last updated November 28, 2024)
In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
Attacker Value
Unknown

CVE-2021-39358

Disclosure Date: August 22, 2021 (last updated November 08, 2023)
In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
Attacker Value
Unknown

CVE-2021-39359

Disclosure Date: August 22, 2021 (last updated November 08, 2023)
In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
Attacker Value
Unknown

CVE-2021-39361

Disclosure Date: August 22, 2021 (last updated November 28, 2024)
In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
Attacker Value
Unknown

CVE-2021-39360

Disclosure Date: August 22, 2021 (last updated November 08, 2023)
In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
Attacker Value
Unknown

CVE-2020-36427

Disclosure Date: July 19, 2021 (last updated November 28, 2024)
GNOME gThumb before 3.10.1 allows an application crash via a malformed JPEG image.
Attacker Value
Unknown

CVE-2021-20240

Disclosure Date: May 28, 2021 (last updated November 08, 2023)
A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victim system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Attacker Value
Unknown

CVE-2009-3721

Disclosure Date: May 26, 2021 (last updated November 29, 2024)
Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.