peter bassill · operator
$ cve CVE-2008-3533 JSON

CVE-2008-3533 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 19.4% (pctl 97)

Patch early

A public exploit exists.

Description

Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to execute arbitrary code via format string specifiers in an invalid URI on the command line, as demonstrated by use of yelp within (1) man or (2) ghelp URI handlers in Firefox, Evolution, and unspecified other programs.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS19.4% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-134
On CISA KEVno
Public exploityes
Published2008-08-18
Last modified2026-06-16

Affected (2)

VendorProduct
gnomegnome
gnomeyelp

Public exploits

SourceTitleDate
exploit-dbYelp 2.23.1 - Invalid URI Format String2008-08-13

References

→ the Explorer  ·  watch your stack  ·  NVD