Gtk is a foundational cross-platform graphical user interface toolkit embedded in numerous desktop applications and display systems across Linux and Unix environments. The observed vulnerability exposure centers on the core Gtk library and its companion components such as Gtk+ and libgio, with classifications reflecting classification uncertainty rather than a clear pattern of specific weakness types. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gtk over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4425MEDIUM libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYS | Sep 18, 2012 | 6.9 | 33 | NO | YES |
CVE-2005-3186HIGH Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes ins | Nov 18, 2005 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gtk.
Media articles that mention a CVE ID that affects a product developed by Gtk — matched by CVE ID, not by vendor name.