Skip to main content

Vendor archive

gnu CVEs

Beta · best-effort

1,205 CVEs tagged to vendor gnu95 Critical, 456 High, 541 Medium, 113 Low, 0 Unrated.

CVE-2018-12886

Published May 22, 2019

stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction se…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5953

Published May 17, 2019

Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11640

Published May 1, 2019

An issue was discovered in GNU recutils 1.8. There is a heap-based buffer overflow in the function rec_fex_parse_str_simple at rec-fex.c in librec.a.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11639

Published May 1, 2019

An issue was discovered in GNU recutils 1.8. There is a stack-based buffer overflow in the function rec_type_check_enum at rec-types.c in librec.a.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11638

Published May 1, 2019

An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at rec-field-name.c in librec.a, leading to a crash.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11637

Published May 1, 2019

An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at rec-rset.c in librec.a, leading to a crash.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7254

Published Apr 10, 2019

The nscd daemon in the GNU C Library (glibc) before version 2.5 does not close incoming client sockets if they cannot be handled by the daemon, allowing local users to carry out a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3590

Published Apr 10, 2019

The getgrouplist function in the GNU C library (glibc) before version 2.3.5, when invoked with a zero argument, writes to the passed pointer even if the specified array size is ze…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-3829

Published Mar 27, 2019

A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server app…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9923

Published Mar 22, 2019

pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9192

Published Feb 26, 2019

In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\1\\1)*' in grep, a dif…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 476-500 of 1,205 CVEsPage 20 of 49