Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Binutils HIGH 7.5
CVE-2017-8397

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 and an invalid…

Patch available
Fix from $1,950 2017-05-01
Binutils HIGH 7.5
CVE-2017-8398

dwarf.c in GNU Binutils 2.28 is vulnerable to an invalid read of size 1 during dumping of debug information from a corrupt binary. This vulnerability…

Patch available
Fix from $1,950 2017-05-01
Gnutls HIGH 7.5
CVE-2017-7869

GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer overflow and heap-based buffer overflow related to the cdk_pkt_read function…

Fix: after 3.5.9
Fix from $1,950 2017-04-14
Osip HIGH 7.5
CVE-2017-7853

In libosip2 in GNU oSIP 4.1.0 and 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msg_osip_body_parse() function defined in …

Patch available
Fix from $1,950 2017-04-13
Osip CRITICAL 9.8
CVE-2016-10324

In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_…

Patch available
Fix from $2,300 2017-04-13
Osip HIGH 7.5
CVE-2016-10325

In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparse…

Patch available
Fix from $1,950 2017-04-13
Osip HIGH 7.5
CVE-2016-10326

In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/o…

Patch available
Fix from $1,950 2017-04-13
A2ps HIGH 7.8
CVE-2015-8107

Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code.

Mitigation only
Fix from $1,950 2017-04-13
Binutils CRITICAL 9.8
CVE-2017-7614

elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a "member access within null pointer" un…

Patch available
Fix from $2,300 2017-04-09
Binutils HIGH 7.5
CVE-2017-7300

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that…

Patch available
Fix from $1,950 2017-03-29
Binutils HIGH 7.5
CVE-2017-7301

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that…

Patch available
Fix from $1,950 2017-03-29
Binutils HIGH 7.5
CVE-2017-7302

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a swap_std_reloc_out function in bfd/aoutx.h that is …

Patch available
Fix from $1,950 2017-03-29
Binutils HIGH 7.5
CVE-2017-7303

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 4) because of m…

Patch available
Fix from $1,950 2017-03-29
Binutils HIGH 7.5
CVE-2017-7304

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 8) because of m…

Patch available
Fix from $1,950 2017-03-29
Binutils MEDIUM 5.5
CVE-2017-7299

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an invalid read (of size 8) because the code to emit …

Patch available
Fix from $1,600 2017-03-29
Bash HIGH 7.8
CVE-2017-5932

The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character a…

Patch available
Fix from $1,950 2017-03-27
Binutils CRITICAL 9.1
CVE-2017-7226

The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-b…

Patch available
Fix from $2,300 2017-03-22
Binutils HIGH 7.5
CVE-2017-7223

GNU assembler in GNU Binutils 2.28 is vulnerable to a global buffer overflow (of size 1) while attempting to unget an EOF character from the input st…

Patch available
Fix from $1,950 2017-03-22
Binutils HIGH 7.5
CVE-2017-7225

The find_nearest_line function in addr2line in GNU Binutils 2.28 does not handle the case where the main file name and the directory name are both em…

Patch available
Fix from $1,950 2017-03-22
Binutils HIGH 7.5
CVE-2017-7227

GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing a bogus input script, leading to a program crash.…

Patch available
Fix from $1,950 2017-03-22
Binutils MEDIUM 5.5
CVE-2017-7224

The find_nearest_line function in objdump in GNU Binutils 2.28 is vulnerable to an invalid write (of size 1) while disassembling a corrupt binary tha…

Patch available
Fix from $1,600 2017-03-22
Binutils CRITICAL 9.8
CVE-2014-9939

ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.

Fix: after 2.25
Fix from $2,300 2017-03-21
Binutils MEDIUM 5.5
CVE-2017-7209

The dump_section_as_bytes function in readelf in GNU Binutils 2.28 accesses a NULL pointer while reading section contents in a corrupt binary, leadin…

Patch available
Fix from $1,600 2017-03-21
Binutils MEDIUM 5.5
CVE-2017-7210

objdump in GNU Binutils 2.28 is vulnerable to multiple heap-based buffer over-reads (of size 1 and size 8) while handling corrupt STABS enum type str…

Patch available
Fix from $1,600 2017-03-21
Screen HIGH 7.8
CVE-2017-5618

GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile…

Fix: after 4.5.0
Fix from $1,950 2017-03-20
Glibc HIGH 8.1
CVE-2015-8983

Integer overflow in the _IO_wstr_overflow function in libio/wstrops.c in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent …

Fix: after 2.21
Fix from $1,950 2017-03-20
Glibc MEDIUM 5.9
CVE-2015-8984

The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (appl…

Fix: after 2.21
Fix from $1,600 2017-03-20
Glibc MEDIUM 5.9
CVE-2015-8985

The pop_fail_stack function in the GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a denial of service (assertion fail…

Fix: 2.28+
Fix from $1,600 2017-03-20
Binutils CRITICAL 9.1
CVE-2017-6969

readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger pro…

No fix yet
Fix from $2,300 2017-03-17
Binutils MEDIUM 5.5
CVE-2017-6965

readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-difference relocations, leading to a …

No fix yet
Fix from $1,600 2017-03-17