Vulnerability index

Browse CVEs

188 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Libextractor MEDIUM 5.5
CVE-2017-15922

In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.

No fix yet
Fix from $1,600 2017-10-26
Libextractor HIGH 7.5
CVE-2017-15600

In GNU Libextractor 1.4, there is a NULL Pointer Dereference in the EXTRACTOR_nsf_extract_method function of plugins/nsf_extractor.c.

No fix yet
Fix from $1,950 2017-10-18
Libextractor HIGH 7.5
CVE-2017-15601

In GNU Libextractor 1.4, there is a heap-based buffer overflow in the EXTRACTOR_png_extract_method function in plugins/png_extractor.c, related to pr…

No fix yet
Fix from $1,950 2017-10-18
Libextractor HIGH 7.5
CVE-2017-15602

In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extrac…

No fix yet
Fix from $1,950 2017-10-18
Libextractor HIGH 7.5
CVE-2017-15267

In GNU Libextractor 1.4, there is a NULL Pointer Dereference in flac_metadata in flac_extractor.c.

No fix yet
Fix from $1,950 2017-10-11
Coreutils MEDIUM 5.1
CVE-2015-1865

fts.c in coreutils 8.4 allows local users to delete arbitrary files.

Mitigation only
Fix from $1,600 2017-09-20
Binutils HIGH 7.8
CVE-2017-14333

The process_version_sections function in readelf.c in GNU Binutils 2.29 allows attackers to cause a denial of service (Integer Overflow, and hang bec…

Mitigation only
Fix from $1,950 2017-09-12
Emacs HIGH 7.5
CVE-2014-9483

Emacs 24.4 allows remote attackers to bypass security restrictions.

No fix yet
Fix from $1,950 2017-08-28
Binutils HIGH 7.5
CVE-2017-13710

The setup_group function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attack…

Mitigation only
Fix from $1,950 2017-08-27
Pspp HIGH 7.5
CVE-2017-12958

There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to …

Mitigation only
Fix from $1,950 2017-08-18
Pspp HIGH 7.5
CVE-2017-12959

There is a reachable assertion abort in the function dict_add_mrset() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will …

Mitigation only
Fix from $1,950 2017-08-18
Pspp HIGH 7.5
CVE-2017-12960

There is a reachable assertion abort in the function dict_rename_var() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will…

Mitigation only
Fix from $1,950 2017-08-18
Pspp HIGH 7.5
CVE-2017-12961

There is an assertion abort in the function parse_attributes() in data/sys-file-reader.c of the libpspp library in GNU PSPP before 1.0.1 that will le…

Mitigation only
Fix from $1,950 2017-08-18
Gnutls HIGH 7.5
CVE-2016-4456

The "GNUTLS_KEYLOGFILE" environment variable in gnutls 3.4.12 allows remote attackers to overwrite and corrupt arbitrary files in the filesystem.

Mitigation only
Fix from $1,950 2017-08-08
Pspp MEDIUM 6.5
CVE-2017-10791

There is an Integer overflow in the hash_int function of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the …

No fix yet
Fix from $1,600 2017-07-02
Pspp MEDIUM 6.5
CVE-2017-10792

There is a NULL Pointer Dereference in the function ll_insert() of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed w…

No fix yet
Fix from $1,600 2017-07-02
Libssp HIGH 7.8
CVE-2016-4973

Binaries compiled against targets that use the libssp library in GCC for stack smashing protection (SSP) might allow local users to perform buffer ov…

Mitigation only
Fix from $1,950 2017-06-07
A2ps HIGH 7.8
CVE-2015-8107

Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code.

Mitigation only
Fix from $1,950 2017-04-13
Binutils CRITICAL 9.1
CVE-2017-6969

readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger pro…

No fix yet
Fix from $2,300 2017-03-17
Binutils MEDIUM 5.5
CVE-2017-6965

readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-difference relocations, leading to a …

No fix yet
Fix from $1,600 2017-03-17
Binutils MEDIUM 5.5
CVE-2017-6966

readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 bin…

No fix yet
Fix from $1,600 2017-03-17
Libiberty HIGH 7.8
CVE-2016-2226EPSS 7%

Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executabl…

No fix yet
Fix from $1,950 2017-02-24
Libiberty MEDIUM 5.5
CVE-2016-4487

Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, r…

Mitigation only
Fix from $1,600 2017-02-24
Libiberty MEDIUM 5.5
CVE-2016-4488

Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, r…

Mitigation only
Fix from $1,600 2017-02-24
Libiberty MEDIUM 5.5
CVE-2016-4489

Integer overflow in the gnu_special function in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a c…

Mitigation only
Fix from $1,600 2017-02-24
Libiberty MEDIUM 5.5
CVE-2016-4490

Integer overflow in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted bina…

Mitigation only
Fix from $1,600 2017-02-24
Mailman HIGH 8.8
CVE-2016-6893

Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the aut…

Mitigation only
Fix from $1,950 2016-09-02
Bash HIGH 10.0
CVE-2014-7186EPSS 64%

The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds arra…

Mitigation only
Fix from $1,950 2014-09-28
Bash HIGH 10.0
CVE-2014-7187EPSS 58%

Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (…

Mitigation only
Fix from $1,950 2014-09-28
Gnutls MEDIUM 5.0
CVE-2014-3465EPSS 7%

The gnutls_x509_dn_oid_name function in lib/x509/common.c in GnuTLS 3.0 before 3.1.20 and 3.2.x before 3.2.10 allows remote attackers to cause a deni…

Mitigation only
Fix from $1,600 2014-06-10