cbcvebase.
CVE-2010-4005
published 2010-11-06

CVE-2010-4005: The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local…

PriorityP419medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.41%
33.6th percentile
The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: vector 1 exists because of an incorrect fix for CVE-2005-4790.2.

Affected

6 ranges
VendorProductVersion rangeFixed in
gnometomboy<= 1.5.2
gnometomboy
gnometomboy
gnometomboy
gnometomboy
gnometomboy>= 0 < 1.15.4-0ubuntu11.15.4-0ubuntu1

CVSS provenance

nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.