Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cflow MEDIUM 6.5
CVE-2019-16166

GNU cflow through 1.6 has a heap-based buffer over-read in the nexttoken function in parser.c.

Fix: after 1.6
Fix from $1,600 2019-09-09
Gcc HIGH 7.5
CVE-2019-15847

The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single cal…

Fix: 7.5.0 / 8.4.0+
Fix from $1,950 2019-09-02
Chess HIGH 7.8
CVE-2019-15767

In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.

No fix yet
Fix from $1,950 2019-08-29
Patch HIGH 7.8
CVE-2018-20969

do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-1…

Fix: after 2.7.6
Fix from $1,950 2019-08-16
Exosip HIGH 7.5
CVE-2014-10375

handle_messages in eXtl_tls.c in eXosip before 5.0.0 mishandles a negative value in a content-length header.

Fix: 5.0.0+
Fix from $1,950 2019-08-14
Gdb HIGH 7.8
CVE-2019-1010180

GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memory Disclosure, and Possible Co…

Fix: 9.1+
Fix from $1,950 2019-07-24
Binutils MEDIUM 5.5
CVE-2019-1010204

GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds …

Fix: after 2.31.1
Fix from $1,600 2019-07-23
Patch MEDIUM 5.9
CVE-2019-13636

In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.

Fix: after 2.7.6
Fix from $1,600 2019-07-17
Glibc CRITICAL 9.8
CVE-2019-1010022

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vec…

No fix yet
Fix from $2,300 2019-07-15
Glibc MEDIUM 5.4
CVE-2019-1010023

GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privil…

No fix yet
Fix from $1,600 2019-07-15
Glibc MEDIUM 5.3
CVE-2019-1010024

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: g…

No fix yet
Fix from $1,600 2019-07-15
Glibc MEDIUM 5.3
CVE-2019-1010025

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is:…

No fix yet
Fix from $1,600 2019-07-15
Gcc HIGH 8.1
CVE-2018-12886

stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumst…

Fix: after 8.0
Fix from $1,950 2019-05-22
Wget CRITICAL 9.8
CVE-2019-5953EPSS 6%

Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspec…

Fix: after 1.20.1
Fix from $2,300 2019-05-17
Recutils HIGH 8.8
CVE-2019-11639

An issue was discovered in GNU recutils 1.8. There is a stack-based buffer overflow in the function rec_type_check_enum at rec-types.c in librec.a.

No fix yet
Fix from $1,950 2019-05-01
Recutils HIGH 8.8
CVE-2019-11640

An issue was discovered in GNU recutils 1.8. There is a heap-based buffer overflow in the function rec_fex_parse_str_simple at rec-fex.c in librec.a.

No fix yet
Fix from $1,950 2019-05-01
Recutils MEDIUM 6.5
CVE-2019-11637

An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at rec-rset.c in librec.a, leadin…

No fix yet
Fix from $1,600 2019-05-01
Recutils MEDIUM 6.5
CVE-2019-11638

An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at rec-field-name.c in librec…

No fix yet
Fix from $1,600 2019-05-01
Glibc CRITICAL 9.8
CVE-2005-3590

The getgrouplist function in the GNU C library (glibc) before version 2.3.5, when invoked with a zero argument, writes to the passed pointer even if …

Fix: 2.3.5+
Fix from $2,300 2019-04-10
Glibc MEDIUM 5.5
CVE-2006-7254

The nscd daemon in the GNU C Library (glibc) before version 2.5 does not close incoming client sockets if they cannot be handled by the daemon, allow…

Fix: 2.5+
Fix from $1,600 2019-04-10
Tar HIGH 7.5
CVE-2019-9923

pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended header…

Fix: 1.32+
Fix from $1,950 2019-03-22
Libredwg HIGH 7.5
CVE-2019-9777

An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dxf_header_write at header_variables…

No fix yet
Fix from $1,950 2019-03-14
Libredwg HIGH 7.5
CVE-2019-9778

An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dwg_dxf_LTYPE at dwg.spec.

No fix yet
Fix from $1,950 2019-03-14
Libredwg HIGH 7.5
CVE-2019-9779

An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (earlier than…

No fix yet
Fix from $1,950 2019-03-14
Libredwg CRITICAL 9.1
CVE-2019-9774

An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function bit_read_B at bits.c.

No fix yet
Fix from $2,300 2019-03-14
Libredwg CRITICAL 9.1
CVE-2019-9775

An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function dwg_dxf_BLOCK_CONTROL at dwg.spec.

No fix yet
Fix from $2,300 2019-03-14
Libredwg HIGH 7.5
CVE-2019-9770

An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for t…

No fix yet
Fix from $1,950 2019-03-14
Libredwg HIGH 7.5
CVE-2019-9771

An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function bit_convert_TU at bits.c.

No fix yet
Fix from $1,950 2019-03-14
Libredwg HIGH 7.5
CVE-2019-9772

An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LEADER at dwg.spec.

No fix yet
Fix from $1,950 2019-03-14
Libredwg HIGH 7.5
CVE-2019-9773

An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for t…

No fix yet
Fix from $1,950 2019-03-14