VYPR

GNU Compiler Collection

by GNU

CVEs (4)

  • CVE-2018-12886HigMay 22, 2019
    risk 0.53cvss 8.1epss 0.02

    stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences when targeting ARM targets that spill the address of the stack protector guard, which allows…

  • CVE-2019-15847HigSep 2, 2019
    risk 0.49cvss 7.5epss 0.03

    The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For…

  • CVE-2017-11671MedJul 26, 2017
    risk 0.26cvss 4.0epss 0.00

    Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can…

  • CVE-2008-1685Apr 6, 2008
    risk 0.00cvss epss 0.01

    gcc 4.2.0 through 4.3.0 in GNU Compiler Collection, when casts are not used, considers the sum of a pointer and an int to be greater than or equal to the pointer, which might lead to removal of length testing code that was intended as a protection mechanism against integer…