VYPR

Vendor CVEs

GNU

All CVEs

1,384 total · sorted by risk
  • CVE-2020-1751MedApr 17, 2020
    risk 0.33cvss 5.1epss 0.01

    An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code…

  • CVE-2015-1865MedSep 20, 2017
    risk 0.33cvss 5.1epss 0.00

    fts.c in coreutils 8.4 allows local users to delete arbitrary files.

  • CVE-2026-18374MedAug 27, 2026
    risk 0.32cvss 4.9epss 0.00

    Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage…

  • CVE-2025-54771MedNov 18, 2025
    risk 0.32cvss 4.9epss 0.00

    A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invalid reference to a file system structure. An attacker could exploit this…

  • CVE-2023-7207MedFeb 29, 2024
    risk 0.32cvss 4.9epss 0.01

    Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.

  • CVE-2018-10845MedAug 22, 2018
    risk 0.32cvss 5.9epss 0.04

    It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.

  • CVE-2018-10844MedAug 22, 2018
    risk 0.32cvss 5.9epss 0.04

    It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data using crafted packets.

  • CVE-2016-4429MedJun 10, 2016
    risk 0.32cvss 5.9epss 0.05

    Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecified other impact via a flood of crafted ICMP and UDP packets.

  • CVE-2026-90804MedSep 14, 2026
    risk 0.31cvss 4.8epss 0.00

    A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_si…

  • CVE-2026-58472MedJul 7, 2026
    risk 0.31cvss 5.9epss 0.00

    GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters…

  • CVE-2026-58471MedJul 7, 2026
    risk 0.31cvss 5.9epss 0.00

    GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When…

  • CVE-2026-41991MedJun 29, 2026
    risk 0.31cvss 4.7epss 0.00

    GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable…

  • CVE-2026-1858MedApr 29, 2026
    risk 0.31cvss 4.8epss 0.00

    wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.

  • CVE-2025-8058MedJul 23, 2025
    risk 0.31cvss —epss 0.00

    The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc that injects random malloc failures. The double free can allow…

  • CVE-2024-33600MedMay 6, 2024
    risk 0.31cvss 5.9epss 0.01

    nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference. This flaw was introduced in glibc 2.15 when the cache was…

  • CVE-2023-25588MedSep 14, 2023
    risk 0.31cvss 4.7epss 0.00

    A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_symtab` function, which may lead to an application crash and local denial of service.

  • CVE-2023-25586MedSep 14, 2023
    risk 0.31cvss 4.7epss 0.00

    A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service.

  • CVE-2023-25585MedSep 14, 2023
    risk 0.31cvss 4.7epss 0.00

    A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.

  • CVE-2023-4039MedSep 13, 2023
    risk 0.31cvss 4.8epss 0.01

    **DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized local variables in your application without this being detected. This stack-protector failure only…

  • CVE-2020-29562MedDec 4, 2020
    risk 0.31cvss 4.8epss 0.02

    The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.

  • CVE-2005-1111MedMay 2, 2005
    risk 0.31cvss 4.7epss 0.00

    Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.

  • CVE-2026-66486MedAug 10, 2026
    risk 0.30cvss —epss 0.00

    GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker can craft a cpio archive containing…

  • CVE-2026-66485MedAug 10, 2026
    risk 0.30cvss —epss 0.00

    GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled pathname during extraction. A malicious cpio…

  • CVE-2026-66484MedAug 10, 2026
    risk 0.30cvss —epss 0.00

    GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar hard-link target is passed to the link_to_name…

  • CVE-2023-0687MedFeb 6, 2023
    risk 0.30cvss 4.6epss 0.01

    A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of the component Call Graph Monitor. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix…

  • CVE-2016-2781MedFeb 7, 2017
    risk 0.30cvss 4.6epss 0.00

    chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

  • CVE-2026-90802MedSep 14, 2026
    risk 0.29cvss 4.4epss 0.00

    A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could…

  • CVE-2026-18477MedAug 3, 2026
    risk 0.29cvss 4.4epss 0.00

    A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being…

  • CVE-2026-18508MedAug 3, 2026
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the…

  • CVE-2025-47815MedMay 10, 2025
    risk 0.29cvss 4.5epss 0.00

    libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in zip-reader.c.

  • CVE-2025-47814MedMay 10, 2025
    risk 0.29cvss 4.5epss 0.00

    libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c.

  • CVE-2023-4156MedSep 25, 2023
    risk 0.29cvss 4.4epss 0.00

    A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.

  • CVE-2020-21490MedAug 22, 2023
    risk 0.29cvss 5.5epss 0.00

    An issue was discovered in GNU Binutils 2.34. It is a memory leak when process microblaze-dis.c. This one will consume memory on each insn disassembled.

  • CVE-2020-19724MedAug 22, 2023
    risk 0.29cvss 5.5epss 0.00

    A memory consumption issue in get_data function in binutils/nm.c in GNU nm before 2.34 allows attackers to cause a denial of service via crafted command.

  • CVE-2022-38533MedAug 26, 2022
    risk 0.29cvss 5.5epss 0.00

    In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file.

  • CVE-2021-3696MedJul 6, 2022
    risk 0.29cvss 4.5epss 0.00

    A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and…

  • CVE-2021-3695MedJul 6, 2022
    risk 0.29cvss 4.5epss 0.00

    A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be…

  • CVE-2014-9637MedAug 25, 2017
    risk 0.29cvss 5.5epss 0.02

    GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.

  • CVE-2016-4492MedFeb 24, 2017
    risk 0.29cvss 4.4epss 0.02

    Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary.

  • CVE-2023-6780MedJan 31, 2024
    risk 0.28cvss 5.3epss 0.03

    An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size…

  • CVE-2021-42096MedOct 21, 2021
    risk 0.28cvss 4.3epss 0.01

    GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.

  • CVE-2020-15011MedJun 24, 2020
    risk 0.28cvss 4.3epss 0.02

    GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.

  • CVE-2026-8674MedSep 17, 2026
    risk 0.27cvss 5.3epss 0.00

    Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process. The…

  • CVE-2026-89092MedSep 11, 2026
    risk 0.27cvss 4.2epss 0.00

    The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of this bug needs a system that has nscd enabled…

  • CVE-2026-71393MedAug 10, 2026
    risk 0.27cvss —epss 0.00

    GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a 32-bit length value from a TrueType font file without overflow checking. On 32-bit targets, a crafted font causes the calculation…

  • CVE-2026-71392MedAug 10, 2026
    risk 0.27cvss —epss 0.00

    GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueType font file, an unguarded addition in the xmalloc allocation call wraps around on 32-bit builds, causing a heap buffer overflow…

  • CVE-2026-71391MedAug 10, 2026
    risk 0.27cvss —epss 0.00

    GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_simple_glyph() and sfnt_vary_compound_glyph() uses a strict greater-than comparison instead of greater-than-or-equal, allowing a…

  • CVE-2026-58470MedJul 7, 2026
    risk 0.27cvss 5.3epss 0.00

    GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range…

  • CVE-2026-9502MedMay 25, 2026
    risk 0.27cvss 5.3epss 0.00

    A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is…

  • CVE-2025-45582MedJul 11, 2025
    risk 0.27cvss 4.1epss 0.00

    GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a…

Page 17 of 28