VYPR

Vendor CVEs

GNU

All CVEs

1,358 total · sorted by risk
  • CVE-2020-21831HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_handles ../../src/decode.c:2637.

  • CVE-2020-21841HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_B ../../src/bits.c:135.

  • CVE-2020-21840HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_search_sentinel ../../src/bits.c:1985.

  • CVE-2020-21838HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_appinfo ../../src/decode.c:2842.

  • CVE-2020-21836HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_preview ../../src/decode.c:3175.

  • CVE-2020-21833HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_classes ../../src/decode.c:2440.

  • CVE-2020-21832HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2417.

  • CVE-2020-21830HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow vulneraibility exists in GNU LibreDWG 0.10 via bit_calc_CRC ../../src/bits.c:2213.

  • CVE-2020-21819HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641via htmlescape ../../programs/escape.c:51.

  • CVE-2020-21818HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:48.

  • CVE-2020-21816HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heab based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:46.

  • CVE-2020-21814HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlwescape ../../programs/escape.c:97.

  • CVE-2021-20231CriMar 12, 2021
    risk 0.57cvss 9.8epss 0.04

    A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.

  • CVE-1999-0199CriOct 6, 2020
    risk 0.57cvss 9.8epss 0.02

    manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation…

  • CVE-2019-20914CriJul 16, 2020
    risk 0.57cvss 9.8epss 0.02

    An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_common_entity_handle_data in common_entity_handle_data.spec.

  • CVE-2017-9105HigJun 18, 2020
    risk 0.57cvss 8.8epss 0.04

    An issue was discovered in adns before 1.5.2. It corrupts a pointer when a nameserver speaks first because of a wrong number of pointer dereferences. This bug may well be exploitable as a remote code execution.

  • CVE-2015-4042CriJan 24, 2020
    risk 0.57cvss 9.8epss 0.02

    Integer overflow in the keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via long strings.

  • CVE-2020-6609HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.02

    GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.

  • CVE-2019-20014HigDec 27, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.

  • CVE-2019-20011HigDec 27, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.

  • CVE-2019-20010HigDec 27, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.

  • CVE-2019-18224CriOct 21, 2019
    risk 0.57cvss 9.8epss 0.04

    idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string.

  • CVE-2019-11640HigMay 1, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in GNU recutils 1.8. There is a heap-based buffer overflow in the function rec_fex_parse_str_simple at rec-fex.c in librec.a.

  • CVE-2019-11639HigMay 1, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in GNU recutils 1.8. There is a stack-based buffer overflow in the function rec_type_check_enum at rec-types.c in librec.a.

  • CVE-2018-16430HigSep 4, 2018
    risk 0.57cvss 8.8epss 0.03

    GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.

  • CVE-2018-14346HigJul 17, 2018
    risk 0.57cvss 8.8epss 0.02

    GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).

  • CVE-2017-18198HigFeb 24, 2018
    risk 0.57cvss 8.8epss 0.03

    print_iso9660_recurse in iso-info.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted iso file.

  • CVE-2017-17531HigDec 14, 2017
    risk 0.57cvss 8.8epss 0.01

    gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

  • CVE-2016-7123HigSep 2, 2016
    risk 0.57cvss 8.8epss 0.02

    Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.

  • CVE-2016-6893HigSep 2, 2016
    risk 0.57cvss 8.8epss 0.02

    Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the authentication of arbitrary users for requests that modify an option, as demonstrated by gaining access to the credentials of a…

  • CVE-2016-4971HigJun 30, 2016
    risk 0.57cvss 8.8epss 0.46

    GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.

  • CVE-2022-2601HigDec 14, 2022
    risk 0.56cvss 8.6epss 0.01

    A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based…

  • CVE-2026-0861HigJan 14, 2026
    risk 0.55cvss 8.4epss 0.00

    Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption. Note that the attacker must have…

  • CVE-2024-53589HigDec 5, 2024
    risk 0.55cvss 8.4epss 0.00

    GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.

  • CVE-2018-1000001HigJan 31, 2018
    risk 0.55cvss 7.8epss 0.13

    In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.

  • CVE-2016-7543HigJan 19, 2017
    risk 0.55cvss 8.4epss 0.01

    Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.

  • CVE-2019-18862HigNov 11, 2019
    risk 0.54cvss 7.8epss 0.01

    maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.

  • CVE-2017-1000408HigFeb 1, 2018
    risk 0.54cvss 7.8epss 0.01

    A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.

  • CVE-2018-6323HigJan 26, 2018
    risk 0.54cvss 7.8epss 0.06

    The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, has an unsigned integer overflow because bfd_size_type multiplication is not used. A crafted ELF file allows remote attackers to cause a denial…

  • CVE-2017-1000366HigJun 19, 2017
    risk 0.54cvss 7.8epss 0.03

    glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent…

  • CVE-2017-9756HigJun 19, 2017
    risk 0.54cvss 7.8epss 0.08

    The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of…

  • CVE-2017-9750HigJun 19, 2017
    risk 0.54cvss 7.8epss 0.08

    opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by…

  • CVE-2017-9749HigJun 19, 2017
    risk 0.54cvss 7.8epss 0.09

    The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during…

  • CVE-2017-9748HigJun 19, 2017
    risk 0.54cvss 7.8epss 0.08

    The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via…

  • CVE-2017-9747HigJun 19, 2017
    risk 0.54cvss 7.8epss 0.08

    The ieee_archive_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact…

  • CVE-2017-9746HigJun 19, 2017
    risk 0.54cvss 7.8epss 0.09

    The disassemble_bytes function in objdump.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of rae insns printing…

  • CVE-2017-9742HigJun 19, 2017
    risk 0.54cvss 7.8epss 0.08

    The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file…

  • CVE-2016-2226HigFeb 24, 2017
    risk 0.54cvss 7.8epss 0.07

    Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer overflow.

  • CVE-2023-4949HigNov 10, 2023
    risk 0.53cvss 8.1epss 0.00

    An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way to exploit a memory corruption in grub’s XFS file system implementation.

  • CVE-2022-28734HigJul 20, 2023
    risk 0.53cvss 8.1epss 0.01

    Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the…

Page 3 of 28