Show filters
309 Total Results
Displaying 71-80 of 309
Sort by:
Attacker Value
Unknown

CVE-2006-7246

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.
Attacker Value
Unknown

CVE-2020-6750

Disclosure Date: January 09, 2020 (last updated November 08, 2023)
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.
Attacker Value
Unknown

CVE-2012-2736

Disclosure Date: December 26, 2019 (last updated November 27, 2024)
In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.
Attacker Value
Unknown

CVE-2012-6111

Disclosure Date: December 20, 2019 (last updated November 27, 2024)
gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function
Attacker Value
Unknown

CVE-2013-4245

Disclosure Date: December 11, 2019 (last updated November 27, 2024)
Orca has arbitrary code execution due to insecure Python module load
Attacker Value
Unknown

CVE-2019-19451

Disclosure Date: November 29, 2019 (last updated November 08, 2023)
When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thumbnailer service, this output will usually be written to disk via the system's logging facility (potentially with elevated privileges), thus filling up the disk and eventually rendering the system unusable. (The filename can be for a nonexistent file.) NOTE: this does not affect an upstream release, but affects certain Linux distribution packages with version numbers such as 0.97.3.
Attacker Value
Unknown

CVE-2019-19308

Disclosure Date: November 27, 2019 (last updated November 27, 2024)
In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing a TTF font file that lacks a name section (due to a g_strconcat call that returns NULL).
Attacker Value
Unknown

CVE-2011-3355

Disclosure Date: November 25, 2019 (last updated November 27, 2024)
evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could use this flaw to obtain login credentials of the victim.
Attacker Value
Unknown

CVE-2012-5535

Disclosure Date: November 25, 2019 (last updated November 27, 2024)
gnome-system-log polkit policy allows arbitrary files on the system to be read
Attacker Value
Unknown

CVE-2011-2897

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw