Gtk

Vendor:

First CVE: Feb 12, 2001 · Active for 25 years

15
Total CVEs
More Total CVEs than 93% of tracked products
1.9
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Gtk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 12, 2001
25 years ago
Most Recent CVE
Feb 21, 2020
2,349 days ago

CVE Severity & Scoring

Gtk15 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network2 (13.3%)
Unknown13 (86.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (13.3%)
High0 (0.0%)
Unknown13 (86.7%)
User Interaction
None2 (13.3%)
Unknown13 (86.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (13.3%)
Unknown13 (86.7%)

Top CVEs

Signals from CVEs in this product scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setui
Feb 12, 20017.233NOYES
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash)
Feb 21, 20209.832NONO
Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan horse uxtheme.dll file in the
Sep 6, 20119.326NONO
GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the
Jan 16, 20157.224NONO
Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arb
Oct 20, 20047.524NONO
Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to ex
Oct 20, 20047.524NONO
io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large numbe
Nov 18, 20057.822NONO
Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large he
Nov 18, 20057.522NONO
Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.
May 2, 20057.522NONO
Untrusted search path vulnerability in gdk/win32/gdkinput-win32.c in GTK+ before 2.21.8 allows local users to gain privileges via a Trojan horse Wintab32.dll file in the current wo
Sep 6, 20116.921NONO

Exploit Exposure

Signals from CVEs in this product scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
13.3% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (15 CVEs).

Media Mentions

Signals from CVEs in this product scope (15 CVEs).

Top CNAs Publishing CVEs For Gtk

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.24.719.84.3%00
2.2.427.59.3%00
2.2.327.59.3%00
2.2.127.59.3%00
2.18.919.84.3%00
2.14.719.84.3%00
2.10.419.84.3%00
2.0.627.59.3%00
2.0.227.59.3%00
1.2.817.21.2%01