Gpsdrive is a GPS navigation and mapping application whose vulnerability profile centers on the core product and its associated scripting utilities, with exposure characterized by improper link-resolution issues and file-access handling weaknesses. These flaws reflect the application's file-system interaction patterns typical of navigation and mapping software that processes user-provided location data and configuration files. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gpsdrive over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-3523HIGH Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (direction) field. | Nov 7, 2005 | 7.5 | 32 | NO | YES |
CVE-2008-5704HIGH src/unit_test.c in gpsdrive (aka gpsdrive-scripts) 2.10~pre4 might allow local users to overwrite arbitrary files via a symlink attack on the /tmp/gpsdrive-unit-test/proc temporary | Dec 22, 2008 | 7.6 | 19 | NO | NO |
CVE-2008-5380MEDIUM gpsdrive (aka gpsdrive-scripts) 2.09 allows local users to overwrite arbitrary files via a symlink attack on an (a) /tmp/geo#####, a (b) /tmp/geocaching.loc, a (c) /tmp/geo#####.*, | Dec 8, 2008 | 6.9 | 18 | NO | NO |
CVE-2008-4959MEDIUM geo-code in gpsdrive-scripts 2.10~pre4 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/geo.google, (2) /tmp/geo.yahoo, (3) /tmp/geo.coords, and (4) | Nov 5, 2008 | 6.9 | 18 | NO | NO |
CVE-2008-5703MEDIUM gpsdrive (aka gpsdrive-scripts) 2.10~pre4 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/.smswatch or (b) /tmp/gpsdrivepos temporary file, rel | Dec 22, 2008 | 6.2 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gpsdrive.
Media articles that mention a CVE ID that affects a product developed by Gpsdrive — matched by CVE ID, not by vendor name.