Vulnerabilities > Gnome

DATE CVE VULNERABILITY TITLE RISK
2011-10-23 CVE-2011-4170 Cross-Site Scripting vulnerability in Gnome Empathy
Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted alias (aka nickname) in a /me event, a different vulnerability than CVE-2011-3635.
network
gnome CWE-79
4.3
2011-10-23 CVE-2011-3635 Cross-Site Scripting vulnerability in Gnome Empathy
Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted alias (aka nickname).
network
gnome CWE-79
4.3
2011-09-02 CVE-2011-2176 Improper Authentication vulnerability in Gnome Networkmanager
GNOME NetworkManager before 0.8.6 does not properly enforce the auth_admin element in PolicyKit, which allows local users to bypass intended wireless network sharing restrictions via unspecified vectors.
local
low complexity
gnome CWE-287
2.1
2011-08-31 CVE-2011-2524 Path Traversal vulnerability in Gnome Libsoup
Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI.
network
low complexity
gnome CWE-22
5.0
2011-06-14 CVE-2011-1943 Information Exposure Through Log Files vulnerability in multiple products
The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0.8.999-3.git20110526 in Fedora 15 creates a log entry containing a certificate password, which allows local users to obtain sensitive information by reading a log file.
local
low complexity
gnome fedoraproject CWE-532
2.1
2011-06-14 CVE-2011-1709 Permissions, Privileges, and Access Controls vulnerability in Gnome GDM
GNOME Display Manager (gdm) before 2.32.2, when glib 2.28 is used, enables execution of a web browser with the uid of the gdm account, which allows local users to gain privileges via vectors involving the x-scheme-handler/http MIME type.
local
low complexity
gnome CWE-264
7.2
2011-03-31 CVE-2011-0727 Link Following vulnerability in Gnome GDM
GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/.
local
gnome CWE-59
6.9
2011-03-07 CVE-2011-0064 The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via crafted OpenType font data that triggers use of an incorrect index.
network
gnome mozilla
6.8
2010-11-06 CVE-2010-4005 Code Injection vulnerability in Gnome Tomboy
The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
local
gnome CWE-94
6.9
2010-11-06 CVE-2010-4000 Permissions, Privileges, and Access Controls vulnerability in Gnome Gnome-Shell 2.31.5
gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
local
gnome CWE-264
6.9