glibc
by glibc
CVEs (27)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2012-0864 | 0.00 | — | 0.03 | May 2, 2013 | Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass the FORTIFY_SOURCE protection mechanism, conduct format string attacks, and write to arbitrary memory via a large number of… | |||
| CVE-2011-4609 | 0.00 | — | 0.02 | May 2, 2013 | The svc_run function in the RPC implementation in glibc before 2.15 allows remote attackers to cause a denial of service (CPU consumption) via a large number of RPC connections. | |||
| CVE-2013-0242 | 0.00 | — | 0.03 | Feb 8, 2013 | Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2.17 and earlier, allows context-dependent attackers to cause a denial of service (memory corruption and crash) via crafted multibyte characters. | |||
| CVE-2008-2357 | 0.00 | — | 0.05 | May 21, 2008 | Stack-based buffer overflow in the split_redraw function in split.c in mtr before 0.73, when invoked with the -p (aka --split) option, allows remote attackers to execute arbitrary code via a crafted DNS PTR record. NOTE: it could be argued that this is a vulnerability in the… | |||
| CVE-2004-1382 | 0.00 | — | 0.00 | Dec 31, 2004 | The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968. | |||
| CVE-2002-1146 | 0.00 | — | 0.03 | Oct 11, 2002 | The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read past the actual boundary… | |||
| CVE-2000-0335 | 0.00 | — | 0.02 | May 3, 2000 | The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results. |
- CVE-2012-0864May 2, 2013risk 0.00cvss —epss 0.03
Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass the FORTIFY_SOURCE protection mechanism, conduct format string attacks, and write to arbitrary memory via a large number of…
- CVE-2011-4609May 2, 2013risk 0.00cvss —epss 0.02
The svc_run function in the RPC implementation in glibc before 2.15 allows remote attackers to cause a denial of service (CPU consumption) via a large number of RPC connections.
- CVE-2013-0242Feb 8, 2013risk 0.00cvss —epss 0.03
Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2.17 and earlier, allows context-dependent attackers to cause a denial of service (memory corruption and crash) via crafted multibyte characters.
- CVE-2008-2357May 21, 2008risk 0.00cvss —epss 0.05
Stack-based buffer overflow in the split_redraw function in split.c in mtr before 0.73, when invoked with the -p (aka --split) option, allows remote attackers to execute arbitrary code via a crafted DNS PTR record. NOTE: it could be argued that this is a vulnerability in the…
- CVE-2004-1382Dec 31, 2004risk 0.00cvss —epss 0.00
The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.
- CVE-2002-1146Oct 11, 2002risk 0.00cvss —epss 0.03
The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read past the actual boundary…
- CVE-2000-0335May 3, 2000risk 0.00cvss —epss 0.02
The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.
Page 2 of 2