CVE-2005-1686 describes a format string vulnerability in gedit 2.10.2, allowing an attacker to trigger a denial of service by crafting a filename containing format string specifiers. This issue, while user-initiated, can be exploited across security boundaries if web browsers or email clients are configured to pass filenames to gedit. The vulnerability has a low CVSS score of 2.6, indicating a network-based attack with high complexity and only partial availability impact. There is an ExploitDB entry for this vulnerability, but it is not listed in CISA's KEV catalog, has no Metasploit or Nuclei modules, and shows no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.10.2CPE matchmatch criteria | cpe:2.3:a:gnome:gedit:2.10.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.