Skip to main content

Vendor archive

gnu CVEs

Beta · best-effort

1,205 CVEs tagged to vendor gnu95 Critical, 456 High, 541 Medium, 113 Low, 0 Unrated.

CVE-2019-7309

Published Feb 3, 2019

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10739

Published Jan 21, 2019

In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitr…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6488

Published Jan 18, 2019

The string component in the GNU C Library (aka glibc or libc6) through 2.28, when running on the x32 architecture, incorrectly attempts to use a 64-bit register for size_t in asse…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6460

Published Jan 16, 2019

An issue was discovered in GNU Recutils 1.8. There is a NULL pointer dereference in the function rec_field_set_name() in the file rec-field.c in librec.a.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6459

Published Jan 16, 2019

An issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_extract_type in rec-utils.c in librec.a.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6458

Published Jan 16, 2019

An issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_buf_new in rec-buf.c when called from rec_parse_rset in rec-parser.c in librec.a.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6457

Published Jan 16, 2019

An issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_aggregate_reg_new in rec-aggregate.c in librec.a.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6456

Published Jan 16, 2019

An issue was discovered in GNU Recutils 1.8. There is a NULL pointer dereference in the function rec_fex_size() in the file rec-fex.c of librec.a.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6455

Published Jan 16, 2019

An issue was discovered in GNU Recutils 1.8. There is a double-free problem in the function rec_mset_elem_destroy() in the file rec-mset.c.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20712

Published Jan 15, 2019

A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentatio…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20673

Published Jan 4, 2019

The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20671

Published Jan 4, 2019

load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer overflow via a crafted sect…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20651

Published Jan 1, 2019

A NULL pointer dereference was discovered in elf_link_add_object_symbols in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20623

Published Dec 31, 2018

In GNU Binutils 2.31.1, there is a use-after-free in the error function in elfcomm.c when called from the process_archive function in readelf.c via a crafted ELF file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 501-525 of 1,205 CVEsPage 21 of 49