Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Guixsd MEDIUM 5.5
CVE-2017-1000455

GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in …

Fix: after 0.13.0
Fix from $1,600 2018-01-02
Global HIGH 8.8
CVE-2017-17531

gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow…

Mitigation only
Fix from $1,950 2017-12-14
Libextractor MEDIUM 6.5
CVE-2017-17440

GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Imp…

Patch available
Fix from $1,600 2017-12-06
Glibc HIGH 8.1
CVE-2017-17426

The malloc function in the GNU C Library (aka glibc or libc6) 2.26 could return a memory block that is too small if an attempt is made to allocate an…

No fix yet
Fix from $1,950 2017-12-05
Binutils HIGH 7.8
CVE-2017-17121

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service (m…

No fix yet
Fix from $1,950 2017-12-04
Binutils HIGH 7.8
CVE-2017-17122

The dump_relocs_in_section function in objdump.c in GNU Binutils 2.29.1 does not check for reloc count integer overflows, which allows remote attacke…

Patch available
Fix from $1,950 2017-12-04
Binutils HIGH 7.8
CVE-2017-17124

The _bfd_coff_read_string_table function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1…

No fix yet
Fix from $1,950 2017-12-04
Binutils HIGH 7.8
CVE-2017-17125

nm.c and objdump.c in GNU Binutils 2.29.1 mishandle certain global symbols, which allows remote attackers to cause a denial of service (_bfd_elf_get_…

Patch available
Fix from $1,950 2017-12-04
Binutils HIGH 7.8
CVE-2017-17126

The load_debug_section function in readelf.c in GNU Binutils 2.29.1 allows remote attackers to cause a denial of service (invalid memory access and a…

Patch available
Fix from $1,950 2017-12-04
Binutils MEDIUM 5.5
CVE-2017-17123

The coff_slurp_reloc_table function in coffcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, al…

No fix yet
Fix from $1,600 2017-12-04
Binutils MEDIUM 5.5
CVE-2017-17080

elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate sizes of core notes, which a…

Mitigation only
Fix from $1,600 2017-11-30
Binutils HIGH 7.8
CVE-2017-16826

The coff_slurp_line_table function in coffcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, all…

Patch available
Fix from $1,950 2017-11-15
Binutils HIGH 7.8
CVE-2017-16827

The aout_get_external_symbols function in aoutx.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, al…

Patch available
Fix from $1,950 2017-11-15
Binutils HIGH 7.8
CVE-2017-16828

The display_debug_frames function in dwarf.c in GNU Binutils 2.29.1 allows remote attackers to cause a denial of service (integer overflow and heap-b…

Patch available
Fix from $1,950 2017-11-15
Binutils HIGH 7.8
CVE-2017-16829

The _bfd_elf_parse_gnu_properties function in elf-properties.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binuti…

Patch available
Fix from $1,950 2017-11-15
Binutils HIGH 7.8
CVE-2017-16830

The print_gnu_property_note function in readelf.c in GNU Binutils 2.29.1 does not have integer-overflow protection on 32-bit platforms, which allows …

Patch available
Fix from $1,950 2017-11-15
Binutils HIGH 7.8
CVE-2017-16831

coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate the symbol count, which …

Patch available
Fix from $1,950 2017-11-15
Binutils HIGH 7.8
CVE-2017-16832

The pe_bfd_read_buildid function in peicode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does n…

Patch available
Fix from $1,950 2017-11-15
Emacs MEDIUM 5.5
CVE-2017-1000383

GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files …

Fix: after 25.3.0
Fix from $1,600 2017-10-31
Binutils HIGH 7.8
CVE-2017-15996

elfcomm.c in readelf in GNU Binutils 2.29 allows remote attackers to cause a denial of service (excessive memory allocation) or possibly have unspeci…

Patch available
Fix from $1,950 2017-10-29
Binutils HIGH 7.5
CVE-2017-15938

dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, miscalculates DW_FORM_ref_addr die refs in th…

Patch available
Fix from $1,950 2017-10-27
Binutils MEDIUM 5.5
CVE-2017-15939

dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles NULL files in a .debug_line file t…

Patch available
Fix from $1,600 2017-10-27
Libextractor MEDIUM 5.5
CVE-2017-15922

In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.

No fix yet
Fix from $1,600 2017-10-26
Glibc CRITICAL 9.8
CVE-2017-15804

The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the…

Fix: after 2.26
Fix from $2,300 2017-10-22
Glibc CRITICAL 9.8
CVE-2017-15670

The GNU C Library (aka glibc or libc6) before 2.27 contains an off-by-one error leading to a heap-based buffer overflow in the glob function in glob.…

Fix: after 2.26
Fix from $2,300 2017-10-20
Glibc MEDIUM 5.9
CVE-2017-15671

The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory …

Fix: after 2.26
Fix from $1,600 2017-10-20
Libextractor HIGH 7.5
CVE-2017-15600

In GNU Libextractor 1.4, there is a NULL Pointer Dereference in the EXTRACTOR_nsf_extract_method function of plugins/nsf_extractor.c.

No fix yet
Fix from $1,950 2017-10-18
Libextractor HIGH 7.5
CVE-2017-15601

In GNU Libextractor 1.4, there is a heap-based buffer overflow in the EXTRACTOR_png_extract_method function in plugins/png_extractor.c, related to pr…

No fix yet
Fix from $1,950 2017-10-18
Libextractor HIGH 7.5
CVE-2017-15602

In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extrac…

No fix yet
Fix from $1,950 2017-10-18
Glibc MEDIUM 6.2
CVE-2011-5320

scanf and related functions in glibc before 2.15 allow local users to cause a denial of service (segmentation fault) via a large string of 0s.

Fix: after 2.14.1
Fix from $1,600 2017-10-18