Glib
Vendor:
First CVE: Mar 14, 2009 · Active for 17 years
37
Total CVEs
More Total CVEs than 97% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Glib over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2009
17 years ago
Most Recent CVE
Jun 30, 2026
24 days ago
CVE Severity & Scoring
Glib37 CVEs
30%
57%
14%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local7 (18.9%)
Network25 (67.6%)
Unknown4 (10.8%)
Physical1 (2.7%)
Adjacent Network0 (0.0%)
Attack Complexity
Low32 (86.5%)
High1 (2.7%)
Unknown4 (10.8%)
User Interaction
None27 (73.0%)
Unknown4 (10.8%)
Required6 (16.2%)
Privileges Required
Low2 (5.4%)
High0 (0.0%)
None31 (83.8%)
Unknown4 (10.8%)
Top CVEs
Signals from CVEs in this product scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-6855HIGH Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of servic | Sep 7, 2016 | 7.5 | 44 | NO | YES |
CVE-2026-58016CRITICAL A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, s | Jun 30, 2026 | 9.1 | 40 | NO | NO |
CVE-2026-58014HIGH A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This f | Jun 30, 2026 | 8.6 | 38 | NO | NO |
CVE-2026-58010HIGH A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the | Jun 30, 2026 | 8.2 | 38 | NO | NO |
CVE-2026-58015HIGH A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from th | Jun 30, 2026 | 7.5 | 36 | NO | NO |
CVE-2025-14087CRITICAL A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer- | Dec 10, 2025 | 9.8 | 36 | NO | NO |
CVE-2026-58013HIGH A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is | Jun 30, 2026 | 8.2 | 35 | NO | NO |
CVE-2026-58012HIGH A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the | Jun 30, 2026 | 8.2 | 35 | NO | NO |
CVE-2026-58011HIGH A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced | Jun 30, 2026 | 7.5 | 34 | NO | NO |
CVE-2018-16428CRITICAL In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference. | Sep 4, 2018 | 9.8 | 33 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (37 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (37 CVEs).
Media Mentions
Signals from CVEs in this product scope (37 CVEs).
Top CNAs Publishing CVEs For Glib
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.9.6 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.9.5 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.9.4 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.9.3 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.9.2 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.9.1 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.9.0 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.88.0 | 3 | 8.0 | 0.3% | 0 | 0 |
| 2.8.6 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.8.5 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.8.4 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.8.3 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.8.2 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.8.1 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.8.0 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.7.7 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.7.6 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.7.5 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.7.4 | 1 | 7.5 | 2.2% | 0 | 0 |
| 2.7.3 | 1 | 7.5 | 2.2% | 0 | 0 |