Vulnerabilities > GNU > Gnump3D > 2.6

DATE CVE VULNERABILITY TITLE RISK
2020-01-24 CVE-2019-3697 Link Following vulnerability in multiple products
UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of gnump3d in openSUSE Leap 15.1 allows local attackers to escalate from user gnump3d to root.
local
low complexity
gnu opensuse CWE-59
7.2
2005-11-18 CVE-2005-3349 Link Following vulnerability in GNU Gnump3D
GNU Gnump3d before 2.9.8 allows local users to modify or delete arbitrary files via a symlink attack on the index.lok temporary file.
local
gnu CWE-59
1.9
2005-11-01 CVE-2005-3425 Cross-Site Scripting vulnerability in GNU gnump3d
Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2005-3424.
network
gnu
4.3
2005-11-01 CVE-2005-3424 Cross-Site Scripting vulnerability in GNU gnump3d Error Page
Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.5 allows remote attackers to inject arbitrary web script or HTML via 404 error pages, a different vulnerability than CVE-2005-3425.
network
gnu
4.3