Libdwarf
Source repositories
CVEs (45)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-8750 | Med | 0.35 | 6.5 | 0.02 | Feb 13, 2017 | libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section marked NOBITS in an ELF file. | ||
| CVE-2016-2091 | Low | 0.22 | 3.3 | 0.01 | Feb 8, 2016 | The dwarf_read_cie_fde_prefix function in dwarf_frame2.c in libdwarf 20151114 allows attackers to cause a denial of service (out-of-bounds read) via a crafted ELF object file. | ||
| CVE-2022-39170 | Hig | 0.00 | 8.8 | 0.01 | Sep 2, 2022 | libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c. | ||
| CVE-2022-34299 | Hig | 0.00 | 8.1 | 0.01 | Jun 23, 2022 | There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b. | ||
| CVE-2022-32200 | Hig | 0.00 | 7.8 | 0.01 | Jun 2, 2022 | libdwarf 0.4.0 has a heap-based buffer over-read in _dwarf_check_string_valid in dwarf_util.c. |
- risk 0.35cvss 6.5epss 0.02
libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section marked NOBITS in an ELF file.
- risk 0.22cvss 3.3epss 0.01
The dwarf_read_cie_fde_prefix function in dwarf_frame2.c in libdwarf 20151114 allows attackers to cause a denial of service (out-of-bounds read) via a crafted ELF object file.
- risk 0.00cvss 8.8epss 0.01
libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.
- risk 0.00cvss 8.1epss 0.01
There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
- risk 0.00cvss 7.8epss 0.01
libdwarf 0.4.0 has a heap-based buffer over-read in _dwarf_check_string_valid in dwarf_util.c.
Page 3 of 3