Known Vulnerabilities for products from Gnome

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Gnome".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-5119 A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are t... Not Provided 2026-03-30 2026-04-01
CVE-2021-42522 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.5 - HIGH 2022-08-25 2023-07-18
CVE-2021-39365 In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it cr... 5.9 - MEDIUM 2021-08-22 2021-12-16
CVE-2021-39361 In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync obj... 5.9 - MEDIUM 2021-08-22 2021-08-30
CVE-2021-39360 In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects... 5.9 - MEDIUM 2021-08-22 2023-11-07
CVE-2021-39359 In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects... 5.9 - MEDIUM 2021-08-22 2023-11-07
CVE-2021-39358 In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync obje... 5.9 - MEDIUM 2021-08-22 2023-11-07
CVE-2021-33516 An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server ... 8.1 - HIGH 2021-05-24 2021-05-28
CVE-2021-28650 autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory... 5.5 - MEDIUM 2021-03-17 2023-11-07
CVE-2021-28153 An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to ... 5.3 - MEDIUM 2021-03-11 2023-11-07
CVE-2021-27219 An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflo... 7.5 - HIGH 2021-02-15 2023-11-07
CVE-2021-27218 An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a bu... 7.5 - HIGH 2021-02-15 2023-11-07
CVE-2021-20315 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 6.1 - MEDIUM 2022-02-18 2022-12-03
CVE-2021-20297 A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkMana... 5.5 - MEDIUM 2021-05-26 2021-06-03
CVE-2021-20240 A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur w... 8.8 - HIGH 2021-05-28 2023-11-07
CVE-2021-3982 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 5.5 - MEDIUM 2022-04-29 2023-02-03
CVE-2021-3800 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 5.5 - MEDIUM 2022-08-23 2023-04-25
CVE-2021-3567 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.5 - HIGH 2022-03-25 2023-07-07
CVE-2021-3349 ** DISPUTED ** GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously ... 3.3 - LOW 2021-02-01 2023-11-07
CVE-2020-36427 GNOME gThumb before 3.10.1 allows an application crash via a malformed JPEG image. 5.5 - MEDIUM 2021-07-19 2021-07-28

Known software with vulnerabilities from Gnome

Type Vendor Product Version
ApplicationGnomeAt-spi2-atk0.1.0
ApplicationGnomeBalsa2.5.0
ApplicationGnomeByzanz-
ApplicationGnomeControl Center-
ApplicationGnomeDia2019-11-27
ApplicationGnomeEpiphany0.7.0
ApplicationGnomeEvince0.1.0
ApplicationGnomeEvolution-
ApplicationGnomeEvolution Data Server3.9.1
ApplicationGnomeEvolution-data-server-
ApplicationGnomeEvolution-data-server33.0.3
ApplicationGnomeEvolution-ews-
ApplicationGnomeEye Of Gnome3.16.5
ApplicationGnomeFile-roller2.32.2
ApplicationGnomeGcab0.4
ApplicationGnomeGdk-pixbuf-
ApplicationGnomeGeary0.1
ApplicationGnomeGedit3.22.1
ApplicationGnomeGlib1.1.0
ApplicationGnomeGlib-networking2.25.0