CVE detail
CVE-2005-4280 — CVE-2005-4280
Published 2005-12-16 · Modified 2026-06-16 · Vendor kitware · Product cmake · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0052
EPSS probability
exploitation probability, 30d
41.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Untrusted search path vulnerability in CMake before 2.2.0-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References