Show filters
309 Total Results
Displaying 31-40 of 309
Sort by:
Attacker Value
Unknown
CVE-2021-45086
Disclosure Date: December 16, 2021 (last updated October 07, 2023)
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.
0
Attacker Value
Unknown
CVE-2021-45085
Disclosure Date: December 16, 2021 (last updated October 07, 2023)
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.
0
Attacker Value
Unknown
CVE-2021-39365
Disclosure Date: August 22, 2021 (last updated November 28, 2024)
In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
0
Attacker Value
Unknown
CVE-2021-39358
Disclosure Date: August 22, 2021 (last updated November 08, 2023)
In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
0
Attacker Value
Unknown
CVE-2021-39359
Disclosure Date: August 22, 2021 (last updated November 08, 2023)
In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
0
Attacker Value
Unknown
CVE-2021-39361
Disclosure Date: August 22, 2021 (last updated November 28, 2024)
In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
0
Attacker Value
Unknown
CVE-2021-39360
Disclosure Date: August 22, 2021 (last updated November 08, 2023)
In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
0
Attacker Value
Unknown
CVE-2020-36427
Disclosure Date: July 19, 2021 (last updated November 28, 2024)
GNOME gThumb before 3.10.1 allows an application crash via a malformed JPEG image.
0
Attacker Value
Unknown
CVE-2021-20240
Disclosure Date: May 28, 2021 (last updated November 08, 2023)
A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victim system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
0
Attacker Value
Unknown
CVE-2009-3721
Disclosure Date: May 26, 2021 (last updated November 29, 2024)
Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.
0