VYPR

Glibc

by GNU

Source repositories

CVEs (178)

  • CVE-2010-4756Mar 2, 2011
    risk 0.00cvss —epss 0.03

    The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an…

  • CVE-2010-3192Oct 14, 2010
    risk 0.00cvss —epss 0.02

    Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0] and backtrace information, which might allow context-dependent attackers to obtain sensitive information from process memory by executing an incorrect program, as demonstrated…

  • CVE-2010-0830Jun 1, 2010
    risk 0.00cvss —epss 0.05

    Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-link.h in ld.so in the GNU C Library (aka glibc or libc6) 2.0.1 through 2.11.1, when the --verify option is used, allows user-assisted remote attackers to execute arbitrary code via a crafted ELF…

  • CVE-2010-0296Jun 1, 2010
    risk 0.00cvss —epss 0.01

    The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or…

  • CVE-2009-4881Jun 1, 2010
    risk 0.00cvss —epss 0.02

    Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted format string, as…

  • CVE-2010-0015Jan 14, 2010
    risk 0.00cvss —epss 0.03

    nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the…

  • CVE-2007-3508Jul 3, 2007
    risk 0.00cvss —epss 0.00

    Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large LD_HWCAP_MASK environment variable value. NOTE: the glibc maintainers state that they do not believe that this issue is…

  • CVE-2004-0968Feb 9, 2005
    risk 0.00cvss —epss 0.00

    The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.

  • CVE-2004-1382Dec 31, 2004
    risk 0.00cvss —epss 0.00

    The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.

  • CVE-2004-1453Dec 31, 2004
    risk 0.00cvss —epss 0.00

    GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program.

  • CVE-2003-0859Dec 15, 2003
    risk 0.00cvss —epss 0.00

    The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.

  • CVE-2003-0689Oct 20, 2003
    risk 0.00cvss —epss 0.02

    The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow.

  • CVE-2002-1265Nov 12, 2002
    risk 0.00cvss —epss 0.03

    The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).

  • CVE-2002-1146Oct 11, 2002
    risk 0.00cvss —epss 0.03

    The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read past the actual boundary…

  • CVE-2002-0684Aug 12, 2002
    risk 0.00cvss —epss 0.06

    Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname…

  • CVE-2001-0886Dec 21, 2001
    risk 0.00cvss —epss 0.01

    Buffer overflow in glob function of glibc allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a glob pattern that ends in a brace "{" character.

  • CVE-2000-0959Dec 19, 2000
    risk 0.00cvss —epss 0.00

    glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.

  • CVE-2000-0335May 3, 2000
    risk 0.00cvss —epss 0.02

    The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.

Page 9 of 9