GNOME's vulnerability profile spans a broadly represented portfolio of foundational Linux desktop and system libraries that reach across thousands of downstream applications and distributions. The exposure concentrates in widely embedded components such as GLib, libsoup, Evolution, and GDK-Pixbuf, where vulnerabilities recur through memory-safety and input-validation weakness classes including buffer-boundary violations, out-of-bounds writes, and improper input handling that are characteristic of C-based system libraries. Because these libraries sit deep in the software supply chain, individual GNOME flaws can propagate across entire distribution ecosystems and the applications that depend on them, making remediation a coordinated effort across many vendors. Vulnerabilities affecting this vendor show a moderate tendency toward public exploit availability, though the exposure severity and in-the-wild exploitation activity vary significantly by individual disclosure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gnome over time
Signals from CVEs in this vendor scope (359 CVEs).
359 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000083HIGH backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR arch | Sep 5, 2017 | 7.8 | 73 | NO | YES |
CVE-2018-10900HIGH Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password hel | Jul 26, 2018 | 7.8 | 47 | NO | YES |
CVE-2008-3533HIGH Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to execute arbitrary code via forma | Aug 18, 2008 | 10.0 | 45 | NO | YES |
CVE-2016-6855HIGH Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of servic | Sep 7, 2016 | 7.5 | 44 | NO | YES |
CVE-2011-0020HIGH Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled | Jan 24, 2011 | 7.6 | 44 | NO | YES |
CVE-2000-0491HIGH Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY | May 24, 2000 | 10.0 | 44 | NO | YES |
CVE-2003-0407HIGH Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string. | Jun 30, 2003 | 10.0 | 43 | NO | YES |
CVE-2026-58016CRITICAL A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, s | Jun 30, 2026 | 9.1 | 40 | NO | NO |
CVE-2017-8871MEDIUM The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted | Jun 12, 2017 | 6.5 | 39 | NO | YES |
CVE-2026-58014HIGH A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This f | Jun 30, 2026 | 8.6 | 38 | NO | NO |
Signals from CVEs in this vendor scope (359 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gnome.
Media articles that mention a CVE ID that affects a product developed by Gnome — matched by CVE ID, not by vendor name.