AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-3304

LOW · CVSS 3.3 EPSS 0.31%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-12-04 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2009-3304
Severity
LOW
CVSS
3.3
EPSS
0.31%

Original NVD Description

GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron/ssh_create.php.