Skip to main content

Vendor archive

gnu CVEs

Beta · best-effort

1,205 CVEs tagged to vendor gnu95 Critical, 456 High, 541 Medium, 113 Low, 0 Unrated.

CVE-2018-20483

Published Dec 26, 2018

set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file,…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-20430

Published Dec 24, 2018

GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRACTOR_common_convert_to_utf8 in…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20230

Published Dec 19, 2018

An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a de…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19591

Published Dec 4, 2018

In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not close…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16868

Published Dec 3, 2018

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run p…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19217

Published Nov 12, 2018

In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stat…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-19211

Published Nov 12, 2018

In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the derefere…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-18701

Published Oct 29, 2018

An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-18700

Published Oct 29, 2018

An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-18484

Published Oct 18, 2018

An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-18483

Published Oct 18, 2018

The get_count function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31, allows remote attackers to cause a denial of service (malloc called with the result of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18309

Published Oct 15, 2018

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory address dereference was discovered in read…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17985

Published Oct 4, 2018

An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption problem caused by the cplus_demangle_type function mak…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17942

Published Oct 3, 2018

The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because memory is not allocated for a trailing '\0' character during %…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17794

Published Sep 30, 2018

An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_to_from when called from itera…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 526-550 of 1,205 CVEsPage 22 of 49