by GNU
CVEs (2)
| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2006-5864 | 0.05 | — | 0.31 | Nov 11, 2006 | Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to execute arbitrary code via a PostScript (PS) file with certain headers that contain long comments, as demonstrated using the (1) DocumentMedia, (2) DocumentPaperSizes, and possibly (3) PageMedia and (4) PaperSize headers. NOTE: this issue can be exploited through other products that use gv such as evince. | ||
| CVE-2010-2056 | 0.00 | — | 0.00 | Jul 22, 2010 | GNU gv before 3.7.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file. |