GNOME / Epiphany
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-18487 | Epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host() | MEDIUM | 5.4 | Aug 6, 2026 |
| CVE-2023-26081 | In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts. | HIGH | 7.5 | Feb 20, 2023 |
| CVE-2022-29536 | In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long… | HIGH | 7.5 | Apr 20, 2022 |
| CVE-2021-45086 | XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js. | MEDIUM | 6.1 | Dec 16, 2021 |
| CVE-2021-45087 | XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title. | MEDIUM | 6.1 | Dec 16, 2021 |
| CVE-2021-45088 | XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page. | MEDIUM | 6.1 | Dec 16, 2021 |
| CVE-2021-45085 | XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS… | MEDIUM | 6.1 | Dec 16, 2021 |
| CVE-2019-6251 | webkitgtk: processing maliciously crafted web content lead to URI spoofing | HIGH | 8.1 | Jan 14, 2019 |
| CVE-2018-12016 | libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via certain window.open an… | HIGH | 7.5 | Jun 7, 2018 |
| CVE-2018-11396 | ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via Java… | HIGH | 7.5 | May 23, 2018 |
| CVE-2017-1000025 | GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager s… | HIGH | 7.5 | Jul 13, 2017 |
| CVE-2010-3312 | Epiphany 2.28 and 2.29, when WebKit and LibSoup are used, unconditionally displays a closed-lock icon for any URL beginning with the https: substring, without… | MEDIUM | 5.8 | Oct 12, 2010 |
| CVE-2008-5985 | Untrusted search path vulnerability in the Python interface in Epiphany 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a… | MEDIUM | 6.9 | Jan 28, 2009 |
| CVE-2005-0238 | The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in U… | MEDIUM | 5.0 | Feb 7, 2005 |
Showing 1 to 13 of 13 CVEs