VYPR

Vendor CVEs

GNU

All CVEs

1,358 total · sorted by risk
  • CVE-2018-10373MedApr 25, 2018
    risk 0.43cvss 6.5epss 0.03

    concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by nm-new.

  • CVE-2017-18199MedFeb 24, 2018
    risk 0.43cvss 6.5epss 0.03

    realloc_symlink in rock.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (NULL Pointer Dereference) via a crafted iso file.

  • CVE-2015-1395HigAug 25, 2017
    risk 0.43cvss 7.5epss 0.11

    Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a diff file name.

  • CVE-2016-6321HigDec 9, 2016
    risk 0.43cvss 7.5epss 0.15

    Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka…

  • CVE-2016-2037MedFeb 22, 2016
    risk 0.43cvss 6.5epss 0.05

    The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.

  • CVE-2026-58469HigJul 7, 2026
    risk 0.42cvss 7.5epss 0.00

    GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only…

  • CVE-2026-9153MedJun 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to insufficient input validation.

  • CVE-2026-48829HigMay 24, 2026
    risk 0.42cvss 7.5epss 0.00

    In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.

  • CVE-2026-42009HigMay 18, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate…

  • CVE-2026-33845HigApr 30, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of…

  • CVE-2026-6238MedApr 28, 2026
    risk 0.42cvss 6.5epss 0.00

    The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to…

  • CVE-2025-61154MedMar 12, 2026
    risk 0.42cvss 6.5epss 0.00

    Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) via the function decompress_R2004_section at decode.c.

  • CVE-2025-15281HigJan 20, 2026
    risk 0.42cvss 7.5epss 0.00

    Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

  • CVE-2025-32990MedJul 10, 2025
    risk 0.42cvss 6.5epss 0.01

    A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory…

  • CVE-2025-0686MedMar 3, 2025
    risk 0.42cvss 6.4epss 0.00

    A flaw was found in grub2. When performing a symlink lookup from a romfs filesystem, grub's romfs filesystem module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for integer overflows. A…

  • CVE-2025-0685MedMar 3, 2025
    risk 0.42cvss 6.4epss 0.00

    A flaw was found in grub2. When reading data from a jfs filesystem, grub's jfs filesystem module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for integer overflows. A maliciouly crafted…

  • CVE-2025-0684MedMar 3, 2025
    risk 0.42cvss 6.4epss 0.00

    A flaw was found in grub2. When performing a symlink lookup from a reiserfs filesystem, grub's reiserfs fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for integer overflows. A maliciouly…

  • CVE-2025-0677MedFeb 19, 2025
    risk 0.42cvss 6.4epss 0.00

    A flaw was found in grub2. When performing a symlink lookup, the grub's UFS module checks the inode's data size to allocate the internal buffer to read the file content, however, it fails to check if the symlink data size has overflown. When this occurs, grub_malloc() may be…

  • CVE-2023-4527MedSep 18, 2023
    risk 0.42cvss 6.5epss 0.02

    A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function…

  • CVE-2020-35357MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected…

  • CVE-2022-28736MedJul 20, 2023
    risk 0.42cvss 6.4epss 0.00

    There's a use-after-free vulnerability in grub_cmd_chainloader() function; The chainloader command is used to boot up operating systems that doesn't support multiboot and do not have direct support from GRUB2. When executing chainloader more than once a use-after-free…

  • CVE-2021-32256MedJul 18, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.

  • CVE-2023-1972MedMay 17, 2023
    risk 0.42cvss 6.5epss 0.01

    A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.

  • CVE-2022-41550MedOct 11, 2022
    risk 0.42cvss 6.5epss 0.01

    GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header.

  • CVE-2021-3826MedSep 1, 2022
    risk 0.42cvss 6.5epss 0.01

    Heap/stack buffer overflow in the dlang_lname function in d-demangle.c in libiberty allows attackers to potentially cause a denial of service (segmentation fault and crash) via a crafted mangled symbol.

  • CVE-2021-45950MedJan 1, 2022
    risk 0.42cvss 6.5epss 0.01

    LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (called from dwg_free_BLOCK and dwg_free_object).

  • CVE-2021-43332MedNov 12, 2021
    risk 0.42cvss 6.5epss 0.01

    In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attack.

  • CVE-2021-39523MedSep 20, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function check_POLYLINE_handles() located in decode.c. It allows an attacker to cause Denial of Service.

  • CVE-2021-39521MedSep 20, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function bit_read_BB() located in bits.c. It allows an attacker to cause Denial of Service.

  • CVE-2021-40491MedSep 3, 2021
    risk 0.42cvss 6.5epss 0.01

    The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.

  • CVE-2020-21839MedMay 17, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU LibreDWG 0.10. Crafted input will lead to an memory leak in dwg_decode_eed ../../src/decode.c:3638.

  • CVE-2020-21835MedMay 17, 2021
    risk 0.42cvss 6.5epss 0.01

    A null pointer deference issue exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2337.

  • CVE-2020-21834MedMay 17, 2021
    risk 0.42cvss 6.5epss 0.01

    A null pointer deference issue exists in GNU LibreDWG 0.10 via get_bmp ../../programs/dwgbmp.c:164.

  • CVE-2020-21817MedMay 17, 2021
    risk 0.42cvss 6.5epss 0.01

    A null pointer dereference issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:29. which causes a denial of service (application crash).

  • CVE-2020-21815MedMay 17, 2021
    risk 0.42cvss 6.5epss 0.01

    A null pointer deference issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114, which causes a denial of service (application crash).

  • CVE-2021-3418MedMar 15, 2021
    risk 0.42cvss 6.4epss 0.00

    If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw…

  • CVE-2020-14308MedJul 29, 2020
    risk 0.42cvss 6.4epss 0.00

    In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested allocation size. This leads the function to return invalid memory allocations which can be further used to cause possible integrity, confidentiality and…

  • CVE-2020-15706MedJul 29, 2020
    risk 0.42cvss 6.4epss 0.01

    GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This…

  • CVE-2020-15705MedJul 29, 2020
    risk 0.42cvss 6.4epss 0.01

    GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without…

  • CVE-2020-15807MedJul 17, 2020
    risk 0.42cvss 6.5epss 0.01

    GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files.

  • CVE-2019-20909HigJul 16, 2020
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LWPOLYLINE in dwg.spec.

  • CVE-2020-12108MedMay 6, 2020
    risk 0.42cvss 6.5epss 0.03

    /options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.

  • CVE-2020-6615MedJan 8, 2020
    risk 0.42cvss 6.5epss 0.02

    GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).

  • CVE-2020-6611MedJan 8, 2020
    risk 0.42cvss 6.5epss 0.02

    GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c.

  • CVE-2020-6610MedJan 8, 2020
    risk 0.42cvss 6.5epss 0.01

    GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.

  • CVE-2019-20015MedDec 27, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in dwg.spec.

  • CVE-2019-20013MedDec 27, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec.

  • CVE-2019-20012MedDec 27, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.spec.

  • CVE-2019-20009MedDec 27, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec.

  • CVE-2019-17451MedOct 10, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm.

Page 10 of 28