
CVE-2022-37290 – Ubuntu Security Notice USN-5786-1
https://notcve.org/view.php?id=CVE-2022-37290
14 Nov 2022 — GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive. GNOME Nautilus 42.2 permite una desreferencia del puntero NULL y el bloqueo de la aplicación get_basename a través de un archivo ZIP pegado. It was discovered that GNOME Files incorrectly handled certain filenames. An attacker could possibly use this issue to cause GNOME Files to crash, leading to a denial of service. • https://gitlab.gnome.org/GNOME/nautilus/-/issues/2376 • CWE-476: NULL Pointer Dereference •

CVE-2019-11461 – Gentoo Linux Security Advisory 201908-027
https://notcve.org/view.php?id=CVE-2019-11461
22 Apr 2019 — An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal, allowing an attacker to escape the sandbox if the thumbnailer has a controlling terminal. This is due to improper filtering of the TIOCSTI ioctl on 64-bit systems, similar to CVE-2019-10063. Fue encontrado un problema en GN... • http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00088.html •

CVE-2017-12447 – Ubuntu Security Notice USN-3912-1
https://notcve.org/view.php?id=CVE-2017-12447
07 Mar 2019 — GdkPixBuf (aka gdk-pixbuf), possibly 2.32.2, as used by GNOME Nautilus 3.14.3 on Ubuntu 16.04, allows attackers to cause a denial of service (stack corruption) or possibly have unspecified other impact via a crafted file folder. GdkPixBuf (también conocido como gdk-pixbuf), posiblemente en la versión 2.32.2, tal y como se utiliza en GNOME Nautilus 3.14.3 en Ubuntu 16.04 permite a los atacantes provocar una denegación de servicio (corrupción de pila) o, posiblemente, otro impacto sin especificar mediante una... • https://bugzilla.gnome.org/show_bug.cgi?id=785979 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-14604 – nautilus: Insufficient validation of trust of .desktop files with execute permission
https://notcve.org/view.php?id=CVE-2017-14604
20 Sep 2017 — GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .desktop file's Name field ends in .pdf but this file's Exec field launches a malicious "sh -c" command. In other words, Nautilus provides no UI indication that a file actually has the potentially unsafe .desktop extension; instead, the UI only shows the .pdf extension. One (slightly) mitigating factor is that an attack requires the .desktop file to have execute p... • http://www.debian.org/security/2017/dsa-3994 • CWE-20: Improper Input Validation CWE-345: Insufficient Verification of Data Authenticity •

CVE-2009-0317
https://notcve.org/view.php?id=CVE-2009-0317
28 Jan 2009 — Untrusted search path vulnerability in the Python language bindings for Nautilus (nautilus-python) allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983). Vulnerabilidad de ruta de búsqueda no confiable en la vinculación del lenguaje Python con Nautilus (nautilus-python) permite a usuarios locales ejecutar código arbitrario a través de un troyano en un fichero Python en el director... • http://www.openwall.com/lists/oss-security/2009/01/26/2 •