HIGH🇵🇱 Wersja polska

CVE-2008-3533

CVSS 10.0v2.0pub. 2008-08-18upd. 2026-04-23

Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to execute arbitrary code via format string specifiers in an invalid URI on the command line, as demonstrated by use of yelp within (1) man or (2) ghelp URI handlers in Firefox, Evolution, and unspecified other programs.

CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
  • Gnome

    APP
    Gnome
    2.202.22
  • Gnome Yelp

    APP
    Gnome
    < 2.24
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-13601HIGH7.1PL ✓same product

Yelp/yelp-xsl: zbyt liberalna polityka CSP umożliwia wyciek plików hosta

CVE-2025-3155HIGH7.4same product

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary script...

CVE-2015-7216MEDIUM6.8same product

The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the J...

CVE-2015-7217MEDIUM4.3same product

The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the T...

CVE-2009-1276LOW2.1same product

XScreenSaver w Sun Solaris 10 i OpenSolaris przed snv_109, a także w Solaris 8 i 9 z GNOME 2.0 lub 2.0.2, umoż...