Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2026-58459

2 месяца назад

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-58459

2 месяца назад

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-58459

2 месяца назад

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-58459

2 месяца назад

gpsd through release-3.27.5, fixed at commit 4c06658, contains a comma ...

CVSS3: 7.8
EPSS: Низкий
rocky логотип

RLSA-2026:51153

около 1 месяца назад

Important: gpsd-minimal security update

EPSS: Низкий
rocky логотип

RLSA-2026:51075

около 1 месяца назад

Important: gpsd security update

EPSS: Низкий
github логотип

GHSA-2hhc-4hqc-4mg8

2 месяца назад

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
EPSS: Низкий
oracle-oval логотип

ELSA-2026-51153

около 1 месяца назад

ELSA-2026-51153: gpsd-minimal security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-51075

около 1 месяца назад

ELSA-2026-51075: gpsd security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-58459

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
2%
Низкий
2 месяца назад
redhat логотип
CVE-2026-58459

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
2%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58459

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
2%
Низкий
2 месяца назад
debian логотип
CVE-2026-58459

gpsd through release-3.27.5, fixed at commit 4c06658, contains a comma ...

CVSS3: 7.8
2%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:51153

Important: gpsd-minimal security update

2%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:51075

Important: gpsd security update

2%
Низкий
около 1 месяца назад
github логотип
GHSA-2hhc-4hqc-4mg8

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
2%
Низкий
2 месяца назад
oracle-oval логотип
ELSA-2026-51153

ELSA-2026-51153: gpsd-minimal security update (IMPORTANT)

2%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-51075

ELSA-2026-51075: gpsd security update (IMPORTANT)

2%
Низкий
около 1 месяца назад

Уязвимостей на страницу