glib
GNOME- Product type
- Other
- Catalog vulnerabilities
- 33
Severity across 9 analyzed records
en
Verify to analyze this security profile
As of 09/13/2026, within CyStack's analyzed data, glib has 7 security vulnerabilities published in the last 90 days. Of these, 2 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of glib and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-58016Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" | Exploitation statusNot known exploited | FixYes | Published06/30/2026 | SeverityHigh |
CVE-2026-58015Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive | Exploitation statusNot known exploited | FixYes | Published06/30/2026 | SeverityMedium |
CVE-2026-58014Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" | Exploitation statusPublic exploit | FixYes | Published06/30/2026 | SeverityHigh |
CVE-2026-58013Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" | Exploitation statusNot known exploited | FixYes | Published06/30/2026 | SeverityMedium |
CVE-2026-58012Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() | Exploitation statusNot known exploited | FixYes | Published06/30/2026 | SeverityMedium |
CVE-2026-58011Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime | Exploitation statusPublic exploit | FixYes | Published06/30/2026 | SeverityMedium |
CVE-2026-58010Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() | Exploitation statusNot known exploited | FixYes | Published06/30/2026 | SeverityMedium |
CVE-2025-14512Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow | Exploitation statusNot known exploited | FixYes | Published12/11/2025 | SeverityMedium |
CVE-2025-14087Glib: glib: buffer underflow in gvariant parser leads to heap corruption | Exploitation statusNot known exploited | FixYes | Published12/10/2025 | SeverityMedium |
CVE-2025-13601Glib: integer overflow in in g_escape_uri_string() | Exploitation statusNot known exploited | FixYes | Published11/26/2025 | SeverityHigh |
CVE-2025-4056Glib: glib crash after long command line | Exploitation statusPublic exploit | FixYes | Published07/28/2025 | SeverityHigh |
CVE-2025-6052Glib: integer overflow in g_string_maybe_expand() leading to potential buffer overflow in glib gstring | Exploitation statusNot known exploited | FixNot confirmed | Published06/13/2025 | SeverityLow |
CVE-2024-52533 | Exploitation statusNot known exploited | FixNot confirmed | Published11/11/2024 | SeverityCritical |
CVE-2024-34397 | Exploitation statusNot known exploited | FixNot confirmed | Published05/07/2024 | SeverityMedium |
CVE-2023-32636 | Exploitation statusNot known exploited | FixNot confirmed | Published09/14/2023 | SeverityMedium |
CVE-2023-32643 | Exploitation statusNot known exploited | FixNot confirmed | Published09/14/2023 | SeverityMedium |
CVE-2023-32611G_variant_byteswap() can take a long time with some non-normal inputs | Exploitation statusNot known exploited | FixNot confirmed | Published09/14/2023 | SeverityMedium |
CVE-2023-29499Gvariant offset table entry size is not checked in is_normal() | Exploitation statusNot known exploited | FixNot confirmed | Published09/14/2023 | SeverityMedium |
CVE-2023-32665Gvariant deserialisation does not match spec for non-normal data | Exploitation statusPublic exploit | FixNot confirmed | Published09/14/2023 | SeverityMedium |
CVE-2021-3800 | Exploitation statusNot confirmed | FixNot confirmed | Published08/23/2022 | SeverityUnknown |
CVE-2021-28153 | Exploitation statusNot confirmed | FixNot confirmed | Published03/11/2021 | SeverityUnknown |
CVE-2021-27219 | Exploitation statusNot confirmed | FixNot confirmed | Published02/15/2021 | SeverityUnknown |
CVE-2021-27218 | Exploitation statusNot confirmed | FixNot confirmed | Published02/15/2021 | SeverityUnknown |
CVE-2020-35457 | Exploitation statusNot confirmed | FixNot confirmed | Published12/14/2020 | SeverityUnknown |
CVE-2020-6750 | Exploitation statusNot confirmed | FixNot confirmed | Published01/09/2020 | SeverityUnknown |
CVE-2019-13012 | Exploitation statusNot confirmed | FixNot confirmed | Published06/28/2019 | SeverityUnknown |
CVE-2019-12450 | Exploitation statusNot confirmed | FixNot confirmed | Published05/29/2019 | SeverityUnknown |
CVE-2019-9633 | Exploitation statusNot confirmed | FixNot confirmed | Published03/08/2019 | SeverityUnknown |
CVE-2018-16428 | Exploitation statusNot confirmed | FixNot confirmed | Published09/04/2018 | SeverityUnknown |
CVE-2018-16429 | Exploitation statusNot confirmed | FixNot confirmed | Published09/04/2018 | SeverityUnknown |
CVE-2012-0039 | Exploitation statusNot known exploited | FixNot confirmed | Published01/14/2012 | SeverityHigh |
CVE-2009-3289 | Exploitation statusNot confirmed | FixNot confirmed | Published09/22/2009 | SeverityUnknown |
CVE-2008-4316 | Exploitation statusNot confirmed | FixNot confirmed | Published03/14/2009 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan