Gnu Gnump3D vulnerabilities

7 known vulnerabilities affecting gnu/gnump3d.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM5LOW1

Vulnerabilities

Page 1 of 1
CVE-2019-3697HIGHCVSS 7.8≤ 3.02020-01-24
CVE-2019-3697 [HIGH] CWE-59 CVE-2019-3697: UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of gnump3d in openSUSE Leap 15 UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of gnump3d in openSUSE Leap 15.1 allows local attackers to escalate from user gnump3d to root. This issue affects: openSUSE Leap 15.1 gnump3d version 3.0-lp151.2.1 and prior versions.
nvd
CVE-2007-6130MEDIUMCVSS 5.0v2.92007-11-26
CVE-2007-6130 [MEDIUM] CWE-287 CVE-2007-6130: gnump3d 2.9final does not apply password protection to its plugins, which might allow remote attacke gnump3d 2.9final does not apply password protection to its plugins, which might allow remote attackers to bypass intended access restrictions.
nvd
CVE-2005-3355MEDIUMCVSS 6.4v2.9v2.9.1+6 more2005-11-18
CVE-2005-3355 [MEDIUM] CWE-22 CVE-2005-3355: Directory traversal vulnerability in GNU Gnump3d before 2.9.8 has unknown impact via "CGI parameters Directory traversal vulnerability in GNU Gnump3d before 2.9.8 has unknown impact via "CGI parameters, and cookie values".
nvd
CVE-2005-3349LOWCVSS 1.9≤ 2.9.7v2.9+6 more2005-11-18
CVE-2005-3349 [LOW] CWE-59 CVE-2005-3349: GNU Gnump3d before 2.9.8 allows local users to modify or delete arbitrary files via a symlink attack GNU Gnump3d before 2.9.8 allows local users to modify or delete arbitrary files via a symlink attack on the index.lok temporary file.
nvd
CVE-2005-3425MEDIUMCVSS 4.3v2.0v2.1+14 more2005-11-01
CVE-2005-3425 [MEDIUM] CVE-2005-3425: Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.6 allows remote attackers to inject a Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2005-3424.
nvd
CVE-2005-3424MEDIUMCVSS 4.3v2.0v2.1+13 more2005-11-01
CVE-2005-3424 [MEDIUM] CVE-2005-3424: Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.5 allows remote attackers to inject a Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.5 allows remote attackers to inject arbitrary web script or HTML via 404 error pages, a different vulnerability than CVE-2005-3425.
nvd
CVE-2005-3123MEDIUMCVSS 5.0v2.9v2.9.1+4 more2005-10-30
CVE-2005-3123 [MEDIUM] CVE-2005-3123: Directory traversal vulnerability in GNUMP3D before 2.9.6 allows remote attackers to read arbitrary Directory traversal vulnerability in GNUMP3D before 2.9.6 allows remote attackers to read arbitrary files via crafted sequences such as "/.//..//////././", which is collapsed into "/.././" after ".." and "//" sequences are removed.
nvd