GNUstep is a lightweight, cross-platform implementation of the Objective-C framework and runtime, with its vulnerability footprint concentrated in the base library that provides core application services and object management. The observed weakness classes center on information exposure and input-validation deficiencies, reflecting the parsing and data-handling responsibilities of a foundational framework library. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gnustep over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-1457MEDIUM Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 allows local users to read arbitrary files via a (1) -c or (2) -a option, which prints file contents in an error message. | May 12, 2010 | 4.9 | 27 | NO | YES |
CVE-2010-1620HIGH Integer overflow in the load_iface function in Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 might allow context-dependent attackers to execute arbitrary code via a (1) fi | May 12, 2010 | 7.2 | 23 | NO | NO |
CVE-2014-2980MEDIUM Tools/gdomap.c in gdomap in GNUstep Base 1.24.6 and earlier, when run in daemon mode, does not properly handle the file descriptor for the logger, which allows remote attackers to | Apr 28, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gnustep.
Media articles that mention a CVE ID that affects a product developed by Gnustep — matched by CVE ID, not by vendor name.