GNOME / Glib
33 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-58016 | Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" | CRITICAL | 9.1 | Jun 30, 2026 |
| CVE-2026-58015 | Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive | HIGH | 7.5 | Jun 30, 2026 |
| CVE-2026-58014 | Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" | HIGH | 8.6 | Jun 30, 2026 |
| CVE-2026-58013 | Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" | HIGH | 8.2 | Jun 30, 2026 |
| CVE-2026-58012 | Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() | HIGH | 8.2 | Jun 30, 2026 |
| CVE-2026-58011 | Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime | HIGH | 7.5 | Jun 30, 2026 |
| CVE-2026-58010 | Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() | HIGH | 8.2 | Jun 30, 2026 |
| CVE-2025-14512 | Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow | MEDIUM | 6.5 | Dec 11, 2025 |
| CVE-2025-14087 | Glib: glib: buffer underflow in gvariant parser leads to heap corruption | CRITICAL | 9.8 | Dec 10, 2025 |
| CVE-2025-13601 | Glib: integer overflow in in g_escape_uri_string() | HIGH | 7.7 | Nov 26, 2025 |
| CVE-2025-4056 | Glib: glib crash after long command line | HIGH | 7.5 | Jul 28, 2025 |
| CVE-2025-6052 | Glib: integer overflow in g_string_maybe_expand() leading to potential buffer overflow in glib gstring | HIGH | 7.5 | Jun 13, 2025 |
| CVE-2024-52533 | glib: buffer overflow in set_connect_msg() | CRITICAL | 9.8 | Nov 11, 2024 |
| CVE-2024-34397 | glib2: Signal subscription vulnerabilities | MEDIUM | 5.2 | May 7, 2024 |
| CVE-2023-32636 | glib: Timeout in fuzz_variant_text | HIGH | 7.5 | Sep 14, 2023 |
| CVE-2023-32643 | glib: Heap-buffer-overflow in g_variant_serialised_get_child | HIGH | 7.8 | Sep 14, 2023 |
| CVE-2023-32611 | G_variant_byteswap() can take a long time with some non-normal inputs | MEDIUM | 5.5 | Sep 14, 2023 |
| CVE-2023-29499 | Gvariant offset table entry size is not checked in is_normal() | HIGH | 7.5 | Sep 14, 2023 |
| CVE-2023-32665 | Gvariant deserialisation does not match spec for non-normal data | MEDIUM | 5.5 | Sep 14, 2023 |
| CVE-2021-3800 | glib2: Possible privilege escalation thourgh pkexec and aliases | MEDIUM | 5.5 | Aug 23, 2022 |
| CVE-2021-28153 | glib: g_file_replace() with G_FILE_CREATE_REPLACE_DESTINATION creates empty target for dangling symlink | MEDIUM | 5.3 | Mar 11, 2021 |
| CVE-2021-27219 | glib: integer overflow in g_bytes_new function on 64-bit platforms due to an implicit cast from 64 bits to 32 bits | CRITICAL | 9.8 | Feb 15, 2021 |
| CVE-2021-27218 | glib: integer overflow in g_byte_array_new_take function when called with a buffer of 4GB or more on a 64-bit platform | HIGH | 7.5 | Feb 15, 2021 |
| CVE-2020-35457 | GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's position is "Rea… | HIGH | 7.8 | Dec 14, 2020 |
| CVE-2020-6750 | glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored | MEDIUM | 6.8 | Jan 9, 2020 |
Showing 1 to 25 of 33 CVEs