Vulnerabilities
Vulnerable Software
Gnome:  Security Vulnerabilities
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-12-16
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-12-16
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-12-16
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-12-16
In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
CVSS Score
5.9
EPSS Score
0.003
Published
2021-08-22
In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
CVSS Score
5.9
EPSS Score
0.003
Published
2021-08-22
In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
CVSS Score
5.9
EPSS Score
0.003
Published
2021-08-22
In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
CVSS Score
5.9
EPSS Score
0.004
Published
2021-08-22
In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
CVSS Score
5.9
EPSS Score
0.001
Published
2021-08-22
GNOME gThumb before 3.10.1 allows an application crash via a malformed JPEG image.
CVSS Score
5.5
EPSS Score
0.002
Published
2021-07-19


Contact Us

Shodan ® - All rights reserved