Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Gnome — Vulnerabilities & Security Advisories 35

Browse all 35 CVE security advisories affecting Gnome. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GNOME serves as a default desktop environment for Linux distributions, providing a user interface for system interaction. Historically, it has faced vulnerabilities across multiple classes, including remote code execution, cross-site scripting, and privilege escalation, with 17 CVEs documented. Security concerns have often centered on components like GNOME Shell and related utilities. Notable incidents include flaws in the Epiphany browser and Nautilus file manager that could lead to information disclosure or arbitrary code execution. The project has addressed these through regular updates, but the complexity of its ecosystem continues to present potential attack surfaces for malicious actors targeting Linux systems.

CVE IDTitleCVSSSeverityPublished
CVE-2026-18487 Epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host() — EpiphanyCWE-451 5.4 Medium2026-08-06
CVE-2026-18358 Gnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing connection throttling allows unauthenticated denial of service — gnome-remote-desktopCWE-400 7.5 High2026-07-31
CVE-2026-66759 Gimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted icns images — GIMPCWE-125 7.1 High2026-07-27
CVE-2026-66758 Gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted fits images — GIMPCWE-190 7.8 High2026-07-27
CVE-2026-66757 Gimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi images — GIMPCWE-190 5.5 Medium2026-07-27
CVE-2026-16768 Gdk-pixbuf: out-of-bounds read in ico parser — gdk-pixbufCWE-125 5.3 Medium2026-07-23
CVE-2026-16615 Librest: weak random number generation in pkce implementation — librestCWE-338 6.8 Medium2026-07-22
CVE-2026-58015 Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive — GLibCWE-22 5.9 Medium2026-06-30
CVE-2026-58016 Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" — GLibCWE-191 7.5 High2026-06-30
CVE-2026-58014 Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" — GLibCWE-193 7.3 High2026-06-30
CVE-2026-58013 Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" — GLibCWE-126 6.5 Medium2026-06-30
CVE-2026-58012 Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() — GLibCWE-126 6.5 Medium2026-06-30
CVE-2026-58010 Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() — GLibCWE-126 6.5 Medium2026-06-30
CVE-2026-58011 Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime — GLibCWE-125 6.5 Medium2026-06-30
CVE-2026-6653 libxml2: Use after free in xmlParseInternalSubset via improper entity resolution handling — libxml2CWE-416--2026-06-22
CVE-2026-2604 Evolution-data-server: evolution data server: arbitrary file deletion via inconsistent uri handling — Evolution Data ServerCWE-73 5.6 Medium2026-06-16
CVE-2026-44931 malcontent: Disk Space Exhaustion via Globally Accessible D-Bus API — malcontentCWE-770--2026-05-13
CVE-2020-37011 Gnome Fonts Viewer 3.34.0 Heap Corruption — Fonts ViewerCWE-787 7.5 High2026-01-29
CVE-2025-14512 Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow — glibCWE-190 6.5 Medium2025-12-11
CVE-2025-14087 Glib: glib: buffer underflow in gvariant parser leads to heap corruption — glibCWE-190 5.6 Medium2025-12-10
CVE-2025-12105 Libsoup: heap use-after-free in libsoup message queue handling during http/2 read completion — libsoupCWE-416 7.5 High2025-10-23
CVE-2025-7424 Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes — libxsltCWE-843 7.5 High2025-07-10
CVE-2025-7425 Libxslt: libxml2: heap use-after-free in libxslt caused by atype corruption in xmlattrptr — libxml2CWE-416 7.8 High2025-07-10
CVE-2025-49795 Libxml: null pointer dereference leads to denial of service (dos) — libxml2CWE-825 7.5 High2025-06-16
CVE-2024-52531 libsoup 安全漏洞 — libsoupCWE-787 6.5 Medium2024-11-11
CVE-2019-25085 GNOME gvdb gvdb-builder.c gvdb_table_write_contents_async use after free — gvdbCWE-416 6.3 Medium2022-12-26
CVE-2020-16125 gdm3 would start gnome-initial-setup if it cannot contact accountservice — GDM3CWE-754 7.2 High2020-11-10
CVE-2012-1096 NetworkManager 信任管理问题漏洞 — NetworkManager 5.5 -2020-03-10
CVE-2013-4166 GNOME Evolution 信息泄露漏洞 — Evolution 7.5 -2020-02-06
CVE-2019-1010238 Gnome Pango 缓冲区错误漏洞 — Pango 9.8 -2019-07-19

This page lists every published CVE security advisory associated with Gnome. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.