Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gnulib HIGH 8.8
CVE-2018-17942

The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because memory is not allocated for a tr…

Fix: 2018-09-23+
Fix from $1,950 2018-10-03
Binutils MEDIUM 6.5
CVE-2018-17794

An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_…

Mitigation only
Fix from $1,600 2018-09-30
Binutils MEDIUM 5.5
CVE-2018-17358

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exist…

No fix yet
Fix from $1,600 2018-09-23
Binutils MEDIUM 5.5
CVE-2018-17359

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exist…

No fix yet
Fix from $1,600 2018-09-23
Binutils MEDIUM 5.5
CVE-2018-17360

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read …

Patch available
Fix from $1,600 2018-09-23
Libtasn1 MEDIUM 5.5
CVE-2018-1000654

GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser ag…

No fix yet
Fix from $1,600 2018-08-20
Libredwg MEDIUM 6.5
CVE-2018-14524

dwg_decode_eed in decode.c in GNU LibreDWG before 0.6 leads to a double free (in dwg_free_eed in free.c) because it does not properly manage the obj-…

Fix: 0.6+
Fix from $1,600 2018-07-23
Libredwg MEDIUM 6.5
CVE-2018-14471

dwg_obj_block_control_get_block_headers in dwg_api.c in GNU LibreDWG 0.5.1048 allows remote attackers to cause a denial of service (NULL pointer dere…

Fix: 0.6+
Fix from $1,600 2018-07-20
Libredwg MEDIUM 6.5
CVE-2018-14443

get_first_owned_object in dwg.c in GNU LibreDWG 0.5.1036 allows remote attackers to cause a denial of service (SEGV).

Fix: 0.6+
Fix from $1,600 2018-07-20
Mailman MEDIUM 6.5
CVE-2018-13796

An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site.

Fix: 2.1.28+
Fix from $1,600 2018-07-12
Binutils HIGH 7.5
CVE-2018-12934

remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OO…

No fix yet
Fix from $1,950 2018-06-28
Binutils MEDIUM 5.5
CVE-2018-12641

An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling…

No fix yet
Fix from $1,600 2018-06-22
Glibc CRITICAL 9.8
CVE-2017-18269

An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.…

Fix: after 2.27
Fix from $2,300 2018-05-18
Binutils MEDIUM 5.5
CVE-2018-9996

An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions…

No fix yet
Fix from $1,600 2018-04-10
Binutils MEDIUM 5.5
CVE-2018-9138

An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.29 and 2.30. Stack Exhaustion occurs in the C++ demangling …

Mitigation only
Fix from $1,600 2018-03-30
Libgfortran CRITICAL 9.8
CVE-2014-5044EPSS 6%

Multiple integer overflows in libgfortran might allow remote attackers to execute arbitrary code or cause a denial of service (Fortran application cr…

Fix: 4.8+
Fix from $2,300 2018-03-07
Binutils MEDIUM 5.5
CVE-2018-7570

The assign_file_positions_for_non_load_sections function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin…

Patch available
Fix from $1,600 2018-02-28
Libcdio CRITICAL 9.8
CVE-2017-18201

An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.

Fix: 2.0.0+
Fix from $2,300 2018-02-26
Libcdio HIGH 8.8
CVE-2017-18198

print_iso9660_recurse in iso-info.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) or…

Fix: 1.0.0+
Fix from $1,950 2018-02-24
Libcdio MEDIUM 6.5
CVE-2017-18199

realloc_symlink in rock.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (NULL Pointer Dereference) via a crafted i…

Fix: 1.0.0+
Fix from $1,600 2018-02-24
Patch HIGH 7.5
CVE-2018-6952EPSS 8%

A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.

Fix: after 2.7.6
Fix from $1,950 2018-02-13
Patch MEDIUM 5.5
CVE-2016-10713

An issue was discovered in GNU patch before 2.7.6. Out-of-bounds access within pch_write_line() in pch.c can possibly lead to DoS via a crafted input…

Fix: 2.7.6+
Fix from $1,600 2018-02-13
Binutils MEDIUM 5.5
CVE-2018-6872

The elf_parse_notes function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote at…

Patch available
Fix from $1,600 2018-02-09
Binutils MEDIUM 5.5
CVE-2018-6759

The bfd_get_debug_link_info_1 function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, has…

Mitigation only
Fix from $1,600 2018-02-06
Glibc CRITICAL 9.8
CVE-2018-6551

The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on i386, did not …

Fix: after 2.26
Fix from $2,300 2018-02-02
Binutils HIGH 7.8
CVE-2018-6543

In GNU Binutils 2.30, there's an integer overflow in the function load_specific_debug_section() in objdump.c, which results in `malloc()` with 0 size…

No fix yet
Fix from $1,950 2018-02-02
Glibc HIGH 7.8
CVE-2017-1000408

A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that…

No fix yet
Fix from $1,950 2018-02-01
Glibc HIGH 7.0
CVE-2017-1000409

A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. Please note th…

No fix yet
Fix from $1,950 2018-02-01
Binutils HIGH 7.8
CVE-2018-6323EPSS 6%

The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, has an unsign…

No fix yet
Fix from $1,950 2018-01-26
Coreutils HIGH 7.1
CVE-2017-18018

In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-…

Fix: after 8.29
Fix from $1,950 2018-01-04