VYPR

Elfutils

by Elfutils Project

Source repositories

CVEs (34)

  • CVE-2017-7607MedApr 9, 2017
    risk 0.36cvss 5.5epss 0.02

    The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.

  • CVE-2016-10255MedMar 23, 2017
    risk 0.36cvss 5.5epss 0.02

    The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted (1) sh_off or (2) sh_size ELF header value, which triggers a memory allocation failure.

  • CVE-2016-10254MedMar 23, 2017
    risk 0.36cvss 5.5epss 0.02

    The allocate_elf function in common.h in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted ELF file, which triggers a memory allocation failure.

  • CVE-2025-1372MedFeb 17, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in GNU elfutils 0.192. It has been declared as critical. Affected by this vulnerability is the function dump_data_section/print_string_section of the file readelf.c of the component eu-readelf. The manipulation of the argument z/x leads to buffer…

  • CVE-2025-1365MedFeb 17, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability, which was classified as critical, was found in GNU elfutils 0.192. This affects the function process_symtab of the file readelf.c of the component eu-readelf. The manipulation of the argument D/a leads to buffer overflow. Local access is required to approach…

  • CVE-2025-1352MedFeb 16, 2025
    risk 0.33cvss 5.0epss 0.01

    A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be…

  • CVE-2018-16062MedAug 29, 2018
    risk 0.29cvss 5.5epss 0.02

    dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.

  • CVE-2024-25260MedFeb 20, 2024
    risk 0.26cvss 4.0epss 0.00

    elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.

  • CVE-2025-1377LowFeb 17, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The…

  • CVE-2025-1371LowFeb 17, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to null pointer dereference. Attacking locally is a…

  • CVE-2025-1376LowFeb 17, 2025
    risk 0.16cvss 2.5epss 0.00

    A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the…

  • CVE-2014-9447Jan 2, 2015
    risk 0.00cvss epss 0.05

    Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.

  • CVE-2014-0172Apr 11, 2014
    risk 0.00cvss epss 0.04

    Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and possibly through 0.158 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed compressed…

  • CVE-2005-1704May 24, 2005
    risk 0.00cvss epss 0.01

    Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a…

Page 2 of 2