Search CVE reports


Toggle filters

1 – 10 of 11 results


CVE-2026-84270

Medium priority
Needs evaluation

(A flaw was found in the MTP backend in gvfs. When reading a file from ...)

1 affected package

gvfs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gvfs Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-84269

Medium priority
Needs evaluation

(A flaw was found in the AFP backend in gvfs. When mounting a share, a ...)

1 affected package

gvfs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gvfs Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-84268

Medium priority
Needs evaluation

(A flaw was found in the SFTP backend in gvfs. When mounting a share an ...)

1 affected package

gvfs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gvfs Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-84267

Medium priority
Needs evaluation

(A flaw was found in the SFTP backend in gvfs. When mounting a share, a ...)

1 affected package

gvfs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gvfs Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-28296

Medium priority

Some fixes available 3 of 6

A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized...

1 affected package

gvfs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gvfs Not affected Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-28295

Medium priority

Some fixes available 3 of 6

A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information...

1 affected package

gvfs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gvfs Not affected Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2019-12795

Medium priority
Fixed

daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this...

1 affected package

gvfs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gvfs Fixed
Show less packages

CVE-2019-12449

Medium priority
Fixed

An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with G_FILE_COPY_ALL_METADATA) operations from admin:// to file:// URIs,...

1 affected package

gvfs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gvfs Fixed
Show less packages

CVE-2019-12448

Medium priority
Fixed

An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c has race conditions because the admin backend doesn't implement query_info_on_read/write.

1 affected package

gvfs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gvfs Fixed
Show less packages

CVE-2019-12447

Medium priority
Fixed

An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used.

1 affected package

gvfs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gvfs Fixed
Show less packages