Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Patch MEDIUM 5.5
CVE-2026-56288

GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive e…

Fix: after 2.8.0
Fix from $1,600 2026-07-09
Patch MEDIUM 5.5
CVE-2026-56289

GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-dif…

Fix: after 2.8.0
Fix from $1,600 2026-07-09
Wget HIGH 7.5
CVE-2026-58469

GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/m…

Fix: after 1.25.0
Fix from $1,950 2026-07-07
Wget HIGH 7.1
CVE-2026-58471

GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that…

Fix: after 1.25.0
Fix from $1,950 2026-07-07
Wget HIGH 7.1
CVE-2026-58472

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c …

Fix: after 1.25.0
Fix from $1,950 2026-07-07
Wget MEDIUM 5.3
CVE-2026-58470

GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c …

Fix: after 1.25.0
Fix from $1,600 2026-07-07
Gzip HIGH 7.5
CVE-2026-41992

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between diffe…

Fix: after 1.14
Fix from $1,950 2026-06-29
Sed HIGH 8.8
CVE-2026-9155

OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via t…

Mitigation only
Fix from $1,950 2026-06-25
Sed MEDIUM 6.5
CVE-2026-9153

Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the express…

Mitigation only
Fix from $1,600 2026-06-25
Sed MEDIUM 6.5
CVE-2026-9154

Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content t…

Mitigation only
Fix from $1,600 2026-06-25
Glibc MEDIUM 6.5
CVE-2026-6238

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content …

Mitigation only
Fix from $1,600 2026-04-28
Glibc HIGH 7.3
CVE-2026-5435

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer …

Mitigation only
Fix from $1,950 2026-04-28
Emacs HIGH 7.1
CVE-2026-6861

A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Grap…

Fix: after 30.2
Fix from $1,950 2026-04-22
Glibc CRITICAL 9.8
CVE-2026-5450

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width spec…

Fix: after 2.43
Fix from $2,300 2026-04-20
Glibc HIGH 7.5
CVE-2026-5928

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byt…

Fix: after 2.43
Fix from $1,950 2026-04-20
Glibc HIGH 7.5
CVE-2026-4046

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or …

Fix: after 2.43
Fix from $1,950 2026-03-30
Glibc HIGH 7.5
CVE-2026-4437

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 t…

Fix: after 2.43
Fix from $1,950 2026-03-20
Glibc MEDIUM 5.4
CVE-2026-4438

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 t…

Fix: after 2.43
Fix from $1,600 2026-03-20
Inetutils CRITICAL 9.8
CVE-2026-32746EPSS 24%

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does …

Fix: after 2.7
Fix from $2,300 2026-03-13
Libredwg MEDIUM 6.5
CVE-2025-61154

Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) …

Fix: after 0.13.3.7835
Fix from $1,600 2026-03-12
Glibc MEDIUM 6.2
CVE-2026-3904

Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under high load…

Fix: 2.37+
Fix from $1,600 2026-03-11
Binutils MEDIUM 6.2
CVE-2025-69648

GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists dat…

Fix: after 2.45.1
Fix from $1,600 2026-03-09
Binutils MEDIUM 6.2
CVE-2025-69647

GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A lo…

Fix: after 2.45.1
Fix from $1,600 2026-03-09
Binutils HIGH 7.5
CVE-2025-69649

GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. D…

Fix: after 2.46
Fix from $1,950 2026-03-06
Binutils HIGH 7.5
CVE-2025-69650

GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT r…

Fix: after 2.46
Fix from $1,950 2026-03-06
Binutils MEDIUM 6.2
CVE-2025-69652

GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF ab…

Fix: after 2.46
Fix from $1,600 2026-03-06
Binutils MEDIUM 5.5
CVE-2025-69645

Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in…

No fix yet
Fix from $1,600 2026-03-06
Binutils MEDIUM 5.5
CVE-2025-69646

Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error …

No fix yet
Fix from $1,600 2026-03-06
Binutils MEDIUM 5.5
CVE-2025-69651

GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed rel…

Fix: after 2.46
Fix from $1,600 2026-03-06
Binutils MEDIUM 5.0
CVE-2025-69644

An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malform…

Fix: 2.46+
Fix from $1,600 2026-03-06