Home/Product/gnome shell
Product

gnome shell

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-43090
>= 43 and < 43.9
A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the lo
5.5MEDIUM
CVE-2021-3982
all versions
Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privi
5.5MEDIUM
CVE-2021-20315
< 3.32.2
A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Applicatio
6.1MEDIUM
CVE-2020-17489
<= 3.36.4
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the passwor
4.3MEDIUM
CVE-2019-3820
>= 3.15.91 and < 3.30.3
It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An atta
4.3MEDIUM
CVE-2017-8288
all versions
gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the loc
8.1HIGH
CVE-2014-7300
all versions
GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all act
CVE-2013-7221
<= 3.9.92
The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Enter a Comma
CVE-2013-7220
<= 3.7.92
js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbitrary comma
CVE-2012-4427
all versions
The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from
CVE-2010-4000
all versions
gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain pri
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin