Skip to main content

Vendor archive

gnu CVEs

Beta · best-effort

1,205 CVEs tagged to vendor gnu95 Critical, 456 High, 541 Medium, 113 Low, 0 Unrated.

CVE-2019-18192

Published Oct 17, 2019

GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable, a similar issue to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17595

Published Oct 14, 2019

There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17594

Published Oct 14, 2019

There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16166

Published Sep 9, 2019

GNU cflow through 1.6 has a heap-based buffer over-read in the nexttoken function in parser.c.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16165

Published Sep 9, 2019

GNU cflow through 1.6 has a use-after-free in the reference function in parser.c.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15847

Published Sep 2, 2019

The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15767

Published Aug 29, 2019

In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20969

Published Aug 16, 2019

do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is spec…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-10375

Published Aug 14, 2019

handle_messages in eXtl_tls.c in eXosip before 5.0.0 mishandles a negative value in a content-length header.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13638

Published Jul 26, 2019

GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacha…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1010180

Published Jul 24, 2019

GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution. The component is…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13636

Published Jul 17, 2019

In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1010025

Published Jul 15, 2019

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's pos…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1010024

Published Jul 15, 2019

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1010023

Published Jul 15, 2019

GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld.…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1010022

Published Jul 15, 2019

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer o…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6711

Published Jun 18, 2019

A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment variable, are printed through…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort
Showing 451-475 of 1,205 CVEsPage 19 of 49