Skip to main content

Vendor archive

gnu CVEs

Beta · best-effort

1,205 CVEs tagged to vendor gnu95 Critical, 456 High, 541 Medium, 113 Low, 0 Unrated.

CVE-2018-6543

Published Feb 2, 2018

In GNU Binutils 2.30, there's an integer overflow in the function load_specific_debug_section() in objdump.c, which results in `malloc()` with 0 size. A crafted ELF file allows re…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000409

Published Feb 1, 2018

A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. Please note that many versions of glibc are…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000408

Published Feb 1, 2018

A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are no…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000001

Published Jan 31, 2018

In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and pote…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2018-6323

Published Jan 26, 2018

The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, has an unsigned integer overflow because bf…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5950

Published Jan 23, 2018

Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL.

CVSS 6.1 · Medium

CVE-2017-18018

Published Jan 4, 2018

In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows lo…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000455

Published Jan 2, 2018

GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in "the store", violating a funda…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17531

Published Dec 14, 2017

gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17440

Published Dec 6, 2017

GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scre…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17426

Published Dec 5, 2017

The malloc function in the GNU C Library (aka glibc or libc6) 2.26 could return a memory block that is too small if an attempt is made to allocate an object whose size is close to…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17126

Published Dec 4, 2017

The load_debug_section function in readelf.c in GNU Binutils 2.29.1 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17125

Published Dec 4, 2017

nm.c and objdump.c in GNU Binutils 2.29.1 mishandle certain global symbols, which allows remote attackers to cause a denial of service (_bfd_elf_get_symbol_version_string buffer o…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17124

Published Dec 4, 2017

The _bfd_coff_read_string_table function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not properly validate t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17123

Published Dec 4, 2017

The coff_slurp_reloc_table function in coffcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17122

Published Dec 4, 2017

The dump_relocs_in_section function in objdump.c in GNU Binutils 2.29.1 does not check for reloc count integer overflows, which allows remote attackers to cause a denial of servic…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17121

Published Dec 4, 2017

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service (memory access violation) or pos…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17080

Published Nov 30, 2017

elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate sizes of core notes, which allows remote attackers to caus…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16879

Published Nov 22, 2017

Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly exe…

CVSS 7.8 · High
evidence mentions
6
Buzz score
37.5
Vendor/product tagsBeta · best-effort

CVE-2017-16832

Published Nov 15, 2017

The pe_bfd_read_buildid function in peicode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate size and offset va…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16831

Published Nov 15, 2017

coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate the symbol count, which allows remote attackers to cau…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16830

Published Nov 15, 2017

The print_gnu_property_note function in readelf.c in GNU Binutils 2.29.1 does not have integer-overflow protection on 32-bit platforms, which allows remote attackers to cause a de…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 601-625 of 1,205 CVEsPage 25 of 49