Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2010-3357

EPSS 0.05% · P17
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2010-3357

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
gnome-subtitles 1.0 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
gnome-subtitles LD_LIBRARY_PATH设计错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
gnome-subtitles 是一款适用于GNOME 桌面环境的字幕编辑器,允许对字幕文件进行编辑、翻译、以及同步操作。 gnome-subtitles 1.0版本在LD_LIBRARY_PATH中放置了零长度的目录名称。本地用户可以借助在当前工作目录中的共享库文件的Trojan木马获得权限提升。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2010-3357

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-3357

登录查看更多情报信息。

Same Patch Batch · n/a · 2010-10-20 · 32 CVEs total

CVE-2010-3366Mn_Fit LD_LIBRARY_PATH设计错误漏洞
CVE-2010-4007Oracle Mojarra加密问题漏洞
CVE-2010-3394TeXmacs LD_LIBRARY_PATH设计错误漏洞
CVE-2010-3393Ecmwf Magics++ magics-config设计错误漏洞
CVE-2010-3389Linux-HA平台OCF Resource Agents设计错误漏洞
CVE-2010-3387Video Disk Recorder 设计错误漏洞
CVE-2010-3386LTTng Userspace Tracer usttrace设计错误漏洞
CVE-2010-3385Herac TuxGuitar LD_LIBRARY_PATH设计错误漏洞
CVE-2010-3384TORCS多个脚本LD_LIBRARY_PATH设计错误漏洞
CVE-2010-3383TeamSpeak多个脚本LD_LIBRARY_PATH设计错误漏洞
CVE-2010-3382Uoregon Tuning和Analysis Utilities tauex设计错误漏洞
CVE-2010-3381Tangerine LD_LIBRARY_PATH设计错误漏洞
CVE-2010-3378Scilab多个脚本LD_LIBRARY_PATH设计错误漏洞
CVE-2010-3377SALOME多个脚本LD_LIBRARY_PATH设计错误漏洞
CVE-2010-3376ROOT多个脚本LD_LIBRARY_PATH设计错误漏洞
CVE-2010-3369Debian mono-debugger多个脚本LD_LIBRARY_PATH设计错误漏洞
CVE-2010-0782IBM WebSphere MQ证书欺骗漏洞
CVE-2010-3365Mistelix LD_LIBRARY_PATH设计错误漏洞
CVE-2010-3364VIPS LD_LIBRARY_PATH设计错误漏洞
CVE-2010-3363roaraudio roarify设计错误漏洞

Showing top 20 of 32 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2010-3357

No comments yet


Leave a comment