VYPR

glibc

by glibc

CVEs (27)

  • CVE-2012-0864May 2, 2013
    risk 0.00cvss epss 0.03

    Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass the FORTIFY_SOURCE protection mechanism, conduct format string attacks, and write to arbitrary memory via a large number of…

  • CVE-2011-4609May 2, 2013
    risk 0.00cvss epss 0.02

    The svc_run function in the RPC implementation in glibc before 2.15 allows remote attackers to cause a denial of service (CPU consumption) via a large number of RPC connections.

  • CVE-2013-0242Feb 8, 2013
    risk 0.00cvss epss 0.03

    Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2.17 and earlier, allows context-dependent attackers to cause a denial of service (memory corruption and crash) via crafted multibyte characters.

  • CVE-2008-2357May 21, 2008
    risk 0.00cvss epss 0.05

    Stack-based buffer overflow in the split_redraw function in split.c in mtr before 0.73, when invoked with the -p (aka --split) option, allows remote attackers to execute arbitrary code via a crafted DNS PTR record. NOTE: it could be argued that this is a vulnerability in the…

  • CVE-2004-1382Dec 31, 2004
    risk 0.00cvss epss 0.00

    The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.

  • CVE-2002-1146Oct 11, 2002
    risk 0.00cvss epss 0.03

    The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read past the actual boundary…

  • CVE-2000-0335May 3, 2000
    risk 0.00cvss epss 0.02

    The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.

Page 2 of 2