Skip to main content

Vendor archive

gnu CVEs

Beta · best-effort

1,205 CVEs tagged to vendor gnu95 Critical, 456 High, 541 Medium, 113 Low, 0 Unrated.

CVE-2018-17360

Published Sep 23, 2018

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in bfd_getl32 in libbfd.c allo…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17359

Published Sep 23, 2018

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exists in bfd_zalloc in opncls.c. A…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17358

Published Sep 23, 2018

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exists in _bfd_stab_section_find_ne…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000654

Published Aug 20, 2018

GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0618

Published Jul 26, 2018

Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14524

Published Jul 23, 2018

dwg_decode_eed in decode.c in GNU LibreDWG before 0.6 leads to a double free (in dwg_free_eed in free.c) because it does not properly manage the obj->eed value after a free occurs.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14471

Published Jul 20, 2018

dwg_obj_block_control_get_block_headers in dwg_api.c in GNU LibreDWG 0.5.1048 allows remote attackers to cause a denial of service (NULL pointer dereference and SEGV) via a crafte…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14443

Published Jul 20, 2018

get_first_owned_object in dwg.c in GNU LibreDWG 0.5.1036 allows remote attackers to cause a denial of service (SEGV).

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13796

Published Jul 12, 2018

An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-12934

Published Jun 28, 2018

remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during exec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12699

Published Jun 23, 2018

finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated b…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-12698

Published Jun 23, 2018

demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an ar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12697

Published Jun 23, 2018

A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12641

Published Jun 22, 2018

An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiber…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11237

Published May 18, 2018

An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer…

CVSS 7.8 · High

CVE-2018-11236

Published May 18, 2018

stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer…

CVSS 9.8 · Critical

CVE-2017-18269

Published May 18, 2018

An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.21 through 2.27 does not corre…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 551-575 of 1,205 CVEsPage 23 of 49