Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-6105

14
FAUCET Score

CVE-2006-6105 describes a format string vulnerability in the GNOME Display Manager's (gdm) host chooser window (gdmchooser). This flaw allows authenticated local users to execute arbitrary code by injecting format string specifiers into a hostname, which are then processed in an error dialog. With a CVSS score of 4.3, this vulnerability is considered medium severity, requiring local access and user authentication for exploitation, leading to potential compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, nor are there publicly available exploit modules or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
2.14.1CPE matchmatch criteria
cpe:2.3:a:gnome:gdm:2.14.1:*:*:*:*:*:*:*
2.16CPE matchmatch criteria
cpe:2.3:a:gnome:gdm:2.16:*:*:*:*:*:*:*
2.16.1CPE matchmatch criteria
cpe:2.3:a:gnome:gdm:2.16.1:*:*:*:*:*:*:*
2.16.2CPE matchmatch criteria
cpe:2.3:a:gnome:gdm:2.16.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:L/AC:L/Au:S/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
LOCAL
Access Complexity
LOW
Authentication
SINGLE
Exploitability Score
3.1
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.40%
Probability of exploitation in next 30 days
EPSS Percentile
32.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0040 is in the 88th percentile among its peer group of 15,938 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2006-6105

CVE-2006-6105

References

ftp.acc.umu.se / pub/GNOME/sources/gdm/2.17/gdm-2.17.4.news
labs.idefense.com / intelligence/vulnerabilities/display.php
Vendor Advisory
secunia.com / advisories/23381
secunia.com / advisories/23385
secunia.com / advisories/23387
secunia.com / advisories/23409
securitytracker.com / id
Patch
securitytracker.com / id
exchange.xforce.ibmcloud.com / vulnerabilities/30896
mandriva.com / security/advisories
novell.com / linux/security/advisories/2006_29_sr.html
osvdb.org / 30848
securityfocus.com / bid/21597
Patch
ubuntu.com / usn/usn-396-1
vupen.com / english/advisories/2006/5015