6.9

CVE-2010-3999

gnc-test-env in GnuCash 2.3.15 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GnucashGnucash Version <= 2.3.15
GnucashGnucash Version1.8.3
GnucashGnucash Version1.8.4
GnucashGnucash Version1.8.5
GnucashGnucash Version2.0.0
GnucashGnucash Version2.0.1
GnucashGnucash Version2.2.0
GnucashGnucash Version2.2.1
GnucashGnucash Version2.2.2
GnucashGnucash Version2.2.3
GnucashGnucash Version2.2.4
GnucashGnucash Version2.2.5
GnucashGnucash Version2.2.6
GnucashGnucash Version2.2.7
GnucashGnucash Version2.2.8
GnucashGnucash Version2.2.9
GnucashGnucash Version2.3.0
GnucashGnucash Version2.3.1
GnucashGnucash Version2.3.2
GnucashGnucash Version2.3.3
GnucashGnucash Version2.3.4
GnucashGnucash Version2.3.5
GnucashGnucash Version2.3.6
GnucashGnucash Version2.3.7
GnucashGnucash Version2.3.8
GnucashGnucash Version2.3.9
GnucashGnucash Version2.3.10
GnucashGnucash Version2.3.11
GnucashGnucash Version2.3.12
GnucashGnucash Version2.3.13
GnucashGnucash Version2.3.14
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.113
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.