Gtk
Vendor:
First CVE: Feb 12, 2001 · Active for 25 years
15
Total CVEs
More Total CVEs than 93% of tracked products
1.9
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Gtk over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 12, 2001
25 years ago
Most Recent CVE
Feb 21, 2020
2,349 days ago
CVE Severity & Scoring
Gtk15 CVEs
33%
53%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network2 (13.3%)
Unknown13 (86.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (13.3%)
High0 (0.0%)
Unknown13 (86.7%)
User Interaction
None2 (13.3%)
Unknown13 (86.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (13.3%)
Unknown13 (86.7%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0084HIGH GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setui | Feb 12, 2001 | 7.2 | 33 | NO | YES |
CVE-2012-0828CRITICAL Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) | Feb 21, 2020 | 9.8 | 32 | NO | NO |
CVE-2010-4833HIGH Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan horse uxtheme.dll file in the | Sep 6, 2011 | 9.3 | 26 | NO | NO |
CVE-2014-1949HIGH GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the | Jan 16, 2015 | 7.2 | 24 | NO | NO |
CVE-2004-0782HIGH Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arb | Oct 20, 2004 | 7.5 | 24 | NO | NO |
CVE-2004-0783HIGH Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to ex | Oct 20, 2004 | 7.5 | 24 | NO | NO |
CVE-2005-2975HIGH io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large numbe | Nov 18, 2005 | 7.8 | 22 | NO | NO |
CVE-2005-2976HIGH Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large he | Nov 18, 2005 | 7.5 | 22 | NO | NO |
CVE-2005-0891HIGH Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image. | May 2, 2005 | 7.5 | 22 | NO | NO |
CVE-2010-4831MEDIUM Untrusted search path vulnerability in gdk/win32/gdkinput-win32.c in GTK+ before 2.21.8 allows local users to gain privileges via a Trojan horse Wintab32.dll file in the current wo | Sep 6, 2011 | 6.9 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
13.3% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Gtk
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.24.7 | 1 | 9.8 | 4.3% | 0 | 0 |
| 2.2.4 | 2 | 7.5 | 9.3% | 0 | 0 |
| 2.2.3 | 2 | 7.5 | 9.3% | 0 | 0 |
| 2.2.1 | 2 | 7.5 | 9.3% | 0 | 0 |
| 2.18.9 | 1 | 9.8 | 4.3% | 0 | 0 |
| 2.14.7 | 1 | 9.8 | 4.3% | 0 | 0 |
| 2.10.4 | 1 | 9.8 | 4.3% | 0 | 0 |
| 2.0.6 | 2 | 7.5 | 9.3% | 0 | 0 |
| 2.0.2 | 2 | 7.5 | 9.3% | 0 | 0 |
| 1.2.8 | 1 | 7.2 | 1.2% | 0 | 1 |