Skip to main content

Vendor archive

gnu CVEs

Beta · best-effort

1,205 CVEs tagged to vendor gnu95 Critical, 456 High, 541 Medium, 113 Low, 0 Unrated.

CVE-2018-9996

Published Apr 10, 2018

An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and th…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000156

Published Apr 6, 2018

GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution.…

CVSS 7.8 · High

CVE-2018-9138

Published Mar 30, 2018

An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.29 and 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libibert…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5044

Published Mar 7, 2018

Multiple integer overflows in libgfortran might allow remote attackers to execute arbitrary code or cause a denial of service (Fortran application crash) via vectors related to ar…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-7570

Published Feb 28, 2018

The assign_file_positions_for_non_load_sections function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote atta…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18201

Published Feb 26, 2018

An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-18199

Published Feb 24, 2018

realloc_symlink in rock.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (NULL Pointer Dereference) via a crafted iso file.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18198

Published Feb 24, 2018

print_iso9660_recurse in iso-info.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified oth…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6952

Published Feb 13, 2018

A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6951

Published Feb 13, 2018

An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_ty…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10713

Published Feb 13, 2018

An issue was discovered in GNU patch before 2.7.6. Out-of-bounds access within pch_write_line() in pch.c can possibly lead to DoS via a crafted input file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6872

Published Feb 9, 2018

The elf_parse_notes function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of s…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6759

Published Feb 6, 2018

The bfd_get_debug_link_info_1 function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, has an unchecked strnlen operatio…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6551

Published Feb 2, 2018

The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on i386, did not properly handle malloc calls w…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 576-600 of 1,205 CVEsPage 24 of 49