Gnucash is a desktop personal and small-business financial management application with a narrowly scoped vulnerability footprint concentrated in the single product itself. The observed weakness classes reflect general application-layer concerns rather than a specific technical pattern. Current exposure counts and severity details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gnucash over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-3999MEDIUM gnc-test-env in GnuCash 2.3.15 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library | Nov 5, 2010 | 6.9 | 21 | NO | NO |
gnucash 2.0.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) gnucash.trace, (2) qof.trace, and (3) qof.trace.[PID] temporary files. | Feb 20, 2007 | 3.6 | 13 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gnucash.
Media articles that mention a CVE ID that affects a product developed by Gnucash — matched by CVE ID, not by vendor name.