VYPR

Vendor CVEs

GNU

All CVEs

1,358 total · sorted by risk
  • CVE-2025-1178MedFeb 11, 2025
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The…

  • CVE-2024-57360MedJan 21, 2025
    risk 0.36cvss 5.5epss 0.00

    https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.

  • CVE-2024-30203MedMar 25, 2024
    risk 0.36cvss 5.5epss 0.01

    In Emacs before 29.3, Gnus treats inline MIME contents as trusted.

  • CVE-2024-0911MedFeb 6, 2024
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash.

  • CVE-2024-0684MedFeb 6, 2024
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.

  • CVE-2022-48065MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.01

    GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c.

  • CVE-2022-48064MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.01

    GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.

  • CVE-2022-48063MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function load_separate_debug_files at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.

  • CVE-2022-47011MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered function parse_stab_struct_fields in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.

  • CVE-2022-47010MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered function pr_function_type in prdbg.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.

  • CVE-2022-47008MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.

  • CVE-2022-47007MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered function stab_demangle_v3_arg in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.

  • CVE-2022-35206MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    Null pointer dereference vulnerability in Binutils readelf 2.38.50 via function read_and_display_attr_value in file dwarf.c.

  • CVE-2022-35205MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Binutils readelf 2.38.50, reachable assertion failure in function display_debug_names allows attackers to cause a denial of service.

  • CVE-2023-40305MedAug 14, 2023
    risk 0.36cvss 5.5epss 0.00

    GNU indent 2.2.13 has a heap-based buffer overflow in search_brace in indent.c via a crafted file.

  • CVE-2023-39130MedJul 25, 2023
    risk 0.36cvss 5.5epss 0.00

    GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap buffer overflow via the function pe_as16() at /gdb/coff-pe-read.c.

  • CVE-2023-39129MedJul 25, 2023
    risk 0.36cvss 5.5epss 0.00

    GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap use after free via the function add_pe_exported_sym() at /gdb/coff-pe-read.c.

  • CVE-2023-39128MedJul 25, 2023
    risk 0.36cvss 5.5epss 0.00

    GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a stack overflow via the function ada_decode at /gdb/ada-lang.c.

  • CVE-2015-20109MedJun 25, 2023
    risk 0.36cvss 5.5epss 0.00

    end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash), as demonstrated by use of the fnmatch library function with the **(!() pattern. NOTE: this…

  • CVE-2022-48303MedJan 30, 2023
    risk 0.36cvss 5.5epss 0.01

    GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has…

  • CVE-2022-4285MedJan 27, 2023
    risk 0.36cvss 5.5epss 0.00

    An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.

  • CVE-2022-27943MedMar 26, 2022
    risk 0.36cvss 5.5epss 0.01

    libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.

  • CVE-2021-46195MedJan 14, 2022
    risk 0.36cvss 5.5epss 0.01

    GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.

  • CVE-2021-46021MedJan 14, 2022
    risk 0.36cvss 5.5epss 0.01

    An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.

  • CVE-2021-45261MedDec 22, 2021
    risk 0.36cvss 5.5epss 0.01

    An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service.

  • CVE-2020-23861MedMay 18, 2021
    risk 0.36cvss 5.5epss 0.01

    A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at libredwg-0.10.1/src/decode_r2007.c:666:5, which causes a denial of service by submitting a dwg file.

  • CVE-2020-23856MedMay 18, 2021
    risk 0.36cvss 5.5epss 0.00

    Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee.

  • CVE-2021-27851MedApr 26, 2021
    risk 0.36cvss 5.5epss 0.00

    A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-user setups in which ’guix-daemon’ runs locally. The attack consists in having an unprivileged user spawn a build process, for instance with `guix…

  • CVE-2021-20284MedMar 26, 2021
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability.

  • CVE-2020-27618MedFeb 26, 2021
    risk 0.36cvss 5.5epss 0.01

    The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications,…

  • CVE-2020-35507MedJan 4, 2021
    risk 0.36cvss 5.5epss 0.01

    There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application…

  • CVE-2020-35496MedJan 4, 2021
    risk 0.36cvss 5.5epss 0.01

    There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability. This flaw…

  • CVE-2020-35495MedJan 4, 2021
    risk 0.36cvss 5.5epss 0.01

    There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw affects binutils versions…

  • CVE-2020-35493MedJan 4, 2021
    risk 0.36cvss 5.5epss 0.01

    A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to…

  • CVE-2020-16599MedDec 9, 2020
    risk 0.36cvss 5.5epss 0.01

    A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in _bfd_elf_get_symbol_version_string, as demonstrated in nm-new, that can cause a denial of service via a crafted file.

  • CVE-2020-16593MedDec 9, 2020
    risk 0.36cvss 5.5epss 0.01

    A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in scan_unit_for_symbols, as demonstrated in addr2line, that can cause a denial of service via a crafted file.

  • CVE-2020-16592MedDec 9, 2020
    risk 0.36cvss 5.5epss 0.01

    A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file.

  • CVE-2020-16591MedDec 9, 2020
    risk 0.36cvss 5.5epss 0.01

    A Denial of Service vulnerability exists in the Binary File Descriptor (BFD) in GNU Binutils 2.35 due to an invalid read in process_symbol_table, as demonstrated in readeif.

  • CVE-2020-16590MedDec 9, 2020
    risk 0.36cvss 5.5epss 0.01

    A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_symbol_table, as demonstrated in readelf, via a crafted file.

  • CVE-2020-14150MedJun 15, 2020
    risk 0.36cvss 5.5epss 0.00

    GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash). NOTE: there is a risk only if Bison is used with untrusted input, and an observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug reports were intended…

  • CVE-2019-20633MedMar 25, 2020
    risk 0.36cvss 5.5epss 0.01

    GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exists because of an incomplete fix for CVE-2018-6952.

  • CVE-2020-10029MedMar 4, 2020
    risk 0.36cvss 5.5epss 0.01

    The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is…

  • CVE-2013-2213MedFeb 11, 2020
    risk 0.36cvss 5.5epss 0.00

    The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the generator…

  • CVE-2019-14444MedJul 30, 2019
    risk 0.36cvss 5.5epss 0.01

    apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf.

  • CVE-2019-14250MedJul 24, 2019
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.

  • CVE-2019-1010204MedJul 23, 2019
    risk 0.36cvss 5.5epss 0.01

    GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread.cc:497, elfcpp/elfcpp_file.h:644. The attack vector is: An…

  • CVE-2019-12972MedJun 26, 2019
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. There is a heap-based buffer over-read in _bfd_doprnt in bfd.c because elf_object_p in elfcode.h mishandles an e_shstrndx section of type SHT_GROUP by omitting…

  • CVE-2006-7254MedApr 10, 2019
    risk 0.36cvss 5.5epss 0.00

    The nscd daemon in the GNU C Library (glibc) before version 2.5 does not close incoming client sockets if they cannot be handled by the daemon, allowing local users to carry out a denial of service attack on the daemon.

  • CVE-2019-9076MedFeb 24, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in elf_read_notes in elf.c.

  • CVE-2019-9074MedFeb 24, 2019
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an out-of-bounds read leading to a SEGV in bfd_getl32 in libbfd.c, when called from pex64_get_runtime_function in pei-x86_64.c.

Page 13 of 28