Glib
GNOME · 33 CVEs
Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
Jun 30, 2026
Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive
Jun 30, 2026
Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"
Jun 30, 2026
Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"
Jun 30, 2026
Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()
Jun 30, 2026
Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime
Jun 30, 2026
Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()
Jun 30, 2026
Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow
Dec 11, 2025
Glib: glib: buffer underflow in gvariant parser leads to heap corruption
Dec 10, 2025
Glib: integer overflow in in g_escape_uri_string()
Nov 26, 2025
Glib: glib crash after long command line
Jul 28, 2025
Glib: integer overflow in g_string_maybe_expand() leading to potential buffer overflow in glib gstring
Jun 13, 2025
glib: buffer overflow in set_connect_msg()
Nov 11, 2024
glib2: Signal subscription vulnerabilities
May 7, 2024
glib: Timeout in fuzz_variant_text
Sep 14, 2023
glib: Heap-buffer-overflow in g_variant_serialised_get_child
Sep 14, 2023
G_variant_byteswap() can take a long time with some non-normal inputs
Sep 14, 2023
Gvariant offset table entry size is not checked in is_normal()
Sep 14, 2023
Gvariant deserialisation does not match spec for non-normal data
Sep 14, 2023
glib2: Possible privilege escalation thourgh pkexec and aliases
Aug 23, 2022
glib: g_file_replace() with G_FILE_CREATE_REPLACE_DESTINATION creates empty target for dangling symlink
Mar 11, 2021
glib: integer overflow in g_bytes_new function on 64-bit platforms due to an implicit cast from 64 bits to 32 bits
Feb 15, 2021
glib: integer overflow in g_byte_array_new_take function when called with a buffer of 4GB or more on a 64-bit platform
Feb 15, 2021
GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entr…
Dec 14, 2020
glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored
Jan 9, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-58016 | Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" | CRITICAL | 0.99% | Jun 30, 2026 |
| CVE-2026-58015 | Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive | HIGH | 0.91% | Jun 30, 2026 |
| CVE-2026-58014 | Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" | HIGH | 0.72% | Jun 30, 2026 |
| CVE-2026-58013 | Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" | HIGH | 0.85% | Jun 30, 2026 |
| CVE-2026-58012 | Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() | HIGH | 0.85% | Jun 30, 2026 |
| CVE-2026-58011 | Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime | HIGH | 0.82% | Jun 30, 2026 |
| CVE-2026-58010 | Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() | HIGH | 0.85% | Jun 30, 2026 |
| CVE-2025-14512 | Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow | MEDIUM | 0.58% | Dec 11, 2025 |
| CVE-2025-14087 | Glib: glib: buffer underflow in gvariant parser leads to heap corruption | CRITICAL | 0.83% | Dec 10, 2025 |
| CVE-2025-13601 | Glib: integer overflow in in g_escape_uri_string() | HIGH | 0.32% | Nov 26, 2025 |
| CVE-2025-4056 | Glib: glib crash after long command line | HIGH | 0.45% | Jul 28, 2025 |
| CVE-2025-6052 | Glib: integer overflow in g_string_maybe_expand() leading to potential buffer overflow in glib gstring | HIGH | 0.52% | Jun 13, 2025 |
| CVE-2024-52533 | glib: buffer overflow in set_connect_msg() | CRITICAL | 1.25% | Nov 11, 2024 |
| CVE-2024-34397 | glib2: Signal subscription vulnerabilities | MEDIUM | 0.76% | May 7, 2024 |
| CVE-2023-32636 | glib: Timeout in fuzz_variant_text | HIGH | 0.78% | Sep 14, 2023 |
| CVE-2023-32643 | glib: Heap-buffer-overflow in g_variant_serialised_get_child | HIGH | 0.36% | Sep 14, 2023 |
| CVE-2023-32611 | G_variant_byteswap() can take a long time with some non-normal inputs | MEDIUM | 0.38% | Sep 14, 2023 |
| CVE-2023-29499 | Gvariant offset table entry size is not checked in is_normal() | HIGH | 0.77% | Sep 14, 2023 |
| CVE-2023-32665 | Gvariant deserialisation does not match spec for non-normal data | MEDIUM | 0.39% | Sep 14, 2023 |
| CVE-2021-3800 | glib2: Possible privilege escalation thourgh pkexec and aliases | MEDIUM | 0.56% | Aug 23, 2022 |
| CVE-2021-28153 | glib: g_file_replace() with G_FILE_CREATE_REPLACE_DESTINATION creates empty target for dangling symlink | MEDIUM | 2.62% | Mar 11, 2021 |
| CVE-2021-27219 | glib: integer overflow in g_bytes_new function on 64-bit platforms due to an implicit cast from 64 bits to 32 bits | CRITICAL | 2.99% | Feb 15, 2021 |
| CVE-2021-27218 | glib: integer overflow in g_byte_array_new_take function when called with a buffer of 4GB or more on a 64-bit platform | HIGH | 4.08% | Feb 15, 2021 |
| CVE-2020-35457 | GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's position is "Rea… | HIGH | 0.57% | Dec 14, 2020 |
| CVE-2020-6750 | glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored | MEDIUM | 2.20% | Jan 9, 2020 |
Showing 1 to 25 of 33 CVEs