Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gnome

First CVE: Sep 23, 1999Active for: 27 yearsTotal CVEs: 359
40.2
VTI Score
Medium

GNOME's vulnerability profile spans a broadly represented portfolio of foundational Linux desktop and system libraries that reach across thousands of downstream applications and distributions. The exposure concentrates in widely embedded components such as GLib, libsoup, Evolution, and GDK-Pixbuf, where vulnerabilities recur through memory-safety and input-validation weakness classes including buffer-boundary violations, out-of-bounds writes, and improper input handling that are characteristic of C-based system libraries. Because these libraries sit deep in the software supply chain, individual GNOME flaws can propagate across entire distribution ecosystems and the applications that depend on them, making remediation a coordinated effort across many vendors. Vulnerabilities affecting this vendor show a moderate tendency toward public exploit availability, though the exposure severity and in-the-wild exploitation activity vary significantly by individual disclosure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
359
Total CVEs
More Total CVEs than 100% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gnome over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 23, 1999
26 years ago
Most Recent CVE
Jun 30, 2026
24 days ago

Products(102 total)

Top CVEs

Signals from CVEs in this vendor scope (359 CVEs).

359 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-1000083HIGH
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR arch
Sep 5, 20177.873NOYES
CVE-2018-10900HIGH
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password hel
Jul 26, 20187.847NOYES
CVE-2008-3533HIGH
Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to execute arbitrary code via forma
Aug 18, 200810.045NOYES
CVE-2016-6855HIGH
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of servic
Sep 7, 20167.544NOYES
CVE-2011-0020HIGH
Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled
Jan 24, 20117.644NOYES
CVE-2000-0491HIGH
Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY
May 24, 200010.044NOYES
CVE-2003-0407HIGH
Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.
Jun 30, 200310.043NOYES
CVE-2026-58016CRITICAL
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, s
Jun 30, 20269.140NONO
CVE-2017-8871MEDIUM
The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted
Jun 12, 20176.539NOYES
CVE-2026-58014HIGH
A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This f
Jun 30, 20268.638NONO
View all 359 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products359 CVEs
9%
46%
40%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local70 (19.5%)
Network124 (34.5%)
Unknown154 (42.9%)
Physical10 (2.8%)
Adjacent Network1 (0.3%)
Attack Complexity
Low182 (50.7%)
High23 (6.4%)
Unknown154 (42.9%)
User Interaction
None133 (37.0%)
Unknown154 (42.9%)
Required72 (20.1%)
Privileges Required
Low34 (9.5%)
High0 (0.0%)
None171 (47.6%)
Unknown154 (42.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (359 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
0.8% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
23 CVEs
6.4% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gnome.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gnome — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gnome's Products

View all 11 CNAs →

Top CWEs