VYPR

Vendor CVEs

GNU

All CVEs

1,358 total · sorted by risk
  • CVE-2023-25586MedSep 14, 2023
    risk 0.31cvss 4.7epss 0.00

    A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service.

  • CVE-2023-25585MedSep 14, 2023
    risk 0.31cvss 4.7epss 0.00

    A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.

  • CVE-2023-4039MedSep 13, 2023
    risk 0.31cvss 4.8epss 0.01

    **DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized local variables in your application without this being detected. This stack-protector failure only…

  • CVE-2020-29562MedDec 4, 2020
    risk 0.31cvss 4.8epss 0.02

    The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.

  • CVE-2005-1111MedMay 2, 2005
    risk 0.31cvss 4.7epss 0.00

    Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.

  • CVE-2026-66486MedAug 10, 2026
    risk 0.30cvss epss 0.00

    GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker can craft a cpio archive containing…

  • CVE-2026-66485MedAug 10, 2026
    risk 0.30cvss epss 0.00

    GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled pathname during extraction. A malicious cpio…

  • CVE-2026-66484MedAug 10, 2026
    risk 0.30cvss epss 0.00

    GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar hard-link target is passed to the link_to_name…

  • CVE-2026-56390MedJul 29, 2026
    risk 0.30cvss epss 0.00

    GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing attacker-supplied grammar, this…

  • CVE-2023-0687MedFeb 6, 2023
    risk 0.30cvss 4.6epss 0.01

    A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of the component Call Graph Monitor. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix…

  • CVE-2016-2781MedFeb 7, 2017
    risk 0.30cvss 4.6epss 0.00

    chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

  • CVE-2026-18477MedAug 3, 2026
    risk 0.29cvss 4.4epss 0.00

    A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being…

  • CVE-2026-18508MedAug 3, 2026
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the…

  • CVE-2025-47815MedMay 10, 2025
    risk 0.29cvss 4.5epss 0.00

    libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in zip-reader.c.

  • CVE-2025-47814MedMay 10, 2025
    risk 0.29cvss 4.5epss 0.00

    libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c.

  • CVE-2023-4156MedSep 25, 2023
    risk 0.29cvss 4.4epss 0.00

    A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.

  • CVE-2020-21490MedAug 22, 2023
    risk 0.29cvss 5.5epss 0.00

    An issue was discovered in GNU Binutils 2.34. It is a memory leak when process microblaze-dis.c. This one will consume memory on each insn disassembled.

  • CVE-2020-19724MedAug 22, 2023
    risk 0.29cvss 5.5epss 0.00

    A memory consumption issue in get_data function in binutils/nm.c in GNU nm before 2.34 allows attackers to cause a denial of service via crafted command.

  • CVE-2022-38533MedAug 26, 2022
    risk 0.29cvss 5.5epss 0.00

    In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file.

  • CVE-2021-3696MedJul 6, 2022
    risk 0.29cvss 4.5epss 0.00

    A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and…

  • CVE-2021-3695MedJul 6, 2022
    risk 0.29cvss 4.5epss 0.00

    A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be…

  • CVE-2014-9637MedAug 25, 2017
    risk 0.29cvss 5.5epss 0.02

    GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.

  • CVE-2016-4492MedFeb 24, 2017
    risk 0.29cvss 4.4epss 0.02

    Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary.

  • CVE-2023-6780MedJan 31, 2024
    risk 0.28cvss 5.3epss 0.03

    An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size…

  • CVE-2021-42096MedOct 21, 2021
    risk 0.28cvss 4.3epss 0.01

    GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.

  • CVE-2020-15011MedJun 24, 2020
    risk 0.28cvss 4.3epss 0.02

    GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.

  • CVE-2026-71393MedAug 10, 2026
    risk 0.27cvss epss 0.00

    GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a 32-bit length value from a TrueType font file without overflow checking. On 32-bit targets, a crafted font causes the calculation…

  • CVE-2026-71392MedAug 10, 2026
    risk 0.27cvss epss 0.00

    GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueType font file, an unguarded addition in the xmalloc allocation call wraps around on 32-bit builds, causing a heap buffer overflow…

  • CVE-2026-71391MedAug 10, 2026
    risk 0.27cvss epss 0.00

    GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_simple_glyph() and sfnt_vary_compound_glyph() uses a strict greater-than comparison instead of greater-than-or-equal, allowing a…

  • CVE-2026-58470MedJul 7, 2026
    risk 0.27cvss 5.3epss 0.00

    GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range…

  • CVE-2026-9502MedMay 25, 2026
    risk 0.27cvss 5.3epss 0.00

    A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is…

  • CVE-2025-45582MedJul 11, 2025
    risk 0.27cvss 4.1epss 0.00

    GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a…

  • CVE-2024-45778MedMar 3, 2025
    risk 0.27cvss 4.1epss 0.00

    A stack overflow flaw was found when reading a BFS file system. A crafted BFS filesystem may lead to an uncontrolled loop, causing grub2 to crash.

  • CVE-2017-11671MedJul 26, 2017
    risk 0.26cvss 4.0epss 0.00

    Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can…

  • CVE-2026-56968LowJun 23, 2026
    risk 0.24cvss 3.7epss 0.00

    GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.

  • CVE-2026-56355LowJun 20, 2026
    risk 0.24cvss 3.7epss 0.00

    GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.

  • CVE-2018-20482MedDec 26, 2018
    risk 0.24cvss 4.7epss 0.01

    GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c) by modifying a file that is supposed to be archived by a different user's…

  • CVE-2026-56391MedJul 24, 2026
    risk 0.23cvss epss 0.00

    GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of…

  • CVE-2024-50610LowOct 27, 2024
    risk 0.23cvss 3.6epss 0.00

    GSL (GNU Scientific Library) through 2.8 has an integer signedness error in gsl_siman_solve_many in siman/siman.c. When params.n_tries is negative, incorrect memory allocation occurs.

  • CVE-2023-2789LowMay 18, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in GNU cflow 1.7. It has been rated as problematic. This issue affects the function func_body/parse_variable_declaration of the file parser.c. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. The…

  • CVE-2026-32772LowMar 16, 2026
    risk 0.22cvss 3.4epss 0.00

    telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.

  • CVE-2025-5278MedMay 27, 2025
    risk 0.22cvss 4.4epss 0.00

    A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a…

  • CVE-2020-35448LowDec 27, 2020
    risk 0.22cvss 3.3epss 0.01

    An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section in…

  • CVE-2026-9529LowMay 26, 2026
    risk 0.21cvss 3.3epss 0.00

    A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function match_BLOCK_HEADER of the file dwggrep.c of the component Dwggrep Utility. Performing a manipulation results in null pointer dereference. The attack requires a local approach.…

  • CVE-2025-11840LowOct 16, 2025
    risk 0.21cvss 3.3epss 0.00

    A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be…

  • CVE-2025-11839LowOct 16, 2025
    risk 0.21cvss 3.3epss 0.00

    A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used…

  • CVE-2025-11495LowOct 8, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has…

  • CVE-2025-11494LowOct 8, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made…

  • CVE-2025-11414LowOct 7, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been…

  • CVE-2025-11413LowOct 7, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and…

Page 17 of 28