Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Binutils MEDIUM 5.5
CVE-2017-6966

readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 bin…

No fix yet
Fix from $1,600 2017-03-17
Glibc HIGH 8.1
CVE-2015-8982

Integer overflow in the strxfrm function in the GNU C Library (aka glibc or libc6) before 2.21 allows context-dependent attackers to cause a denial o…

Fix: after 2.20
Fix from $1,950 2017-03-15
Wget MEDIUM 6.1
CVE-2017-6508

CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via C…

Fix: after 1.19.1
Fix from $1,600 2017-03-07
Glibc MEDIUM 5.9
CVE-2016-10228

The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSL…

Fix: after 2.25
Fix from $1,600 2017-03-02
Libiberty HIGH 7.8
CVE-2016-2226EPSS 7%

Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executabl…

No fix yet
Fix from $1,950 2017-02-24
Libiberty MEDIUM 5.5
CVE-2016-4487

Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, r…

Mitigation only
Fix from $1,600 2017-02-24
Libiberty MEDIUM 5.5
CVE-2016-4488

Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, r…

Mitigation only
Fix from $1,600 2017-02-24
Libiberty MEDIUM 5.5
CVE-2016-4489

Integer overflow in the gnu_special function in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a c…

Mitigation only
Fix from $1,600 2017-02-24
Libiberty MEDIUM 5.5
CVE-2016-4490

Integer overflow in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted bina…

Mitigation only
Fix from $1,600 2017-02-24
Libiberty MEDIUM 5.5
CVE-2016-4491

The d_print_comp function in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a cra…

Patch available
Fix from $1,600 2017-02-24
Libiberty MEDIUM 5.5
CVE-2016-4493

The demangle_template_value_parm and do_hpacc_template_literal functions in cplus-dem.c in libiberty allow remote attackers to cause a denial of serv…

Patch available
Fix from $1,600 2017-02-24
Glibc HIGH 7.5
CVE-2016-5417

Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows…

Fix: after 2.23
Fix from $1,950 2017-02-17
Libiberty HIGH 7.5
CVE-2016-6131

The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the ref…

Patch available
Fix from $1,950 2017-02-07
Chess CRITICAL 9.8
CVE-2015-8972

Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent a…

Fix: 6.2.4+
Fix from $2,300 2017-01-23
Tar HIGH 7.5
CVE-2016-6321EPSS 15%

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended p…

Patch available
Fix from $1,950 2016-12-09
Gnutls HIGH 7.5
CVE-2016-7444

The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCS…

Fix: after 3.4.14
Fix from $1,950 2016-09-27
Wget HIGH 8.1
CVE-2016-7098EPSS 7%

Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass int…

Fix: after 1.17
Fix from $1,950 2016-09-26
Libidn HIGH 7.5
CVE-2016-6263

The stringprep_utf8_nfkc_normalize function in lib/nfkc.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-…

Fix: after 1.32
Fix from $1,950 2016-09-07
Mailman HIGH 8.8
CVE-2016-7123

Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authent…

Fix: after 2.1.14
Fix from $1,950 2016-09-02
Mailman HIGH 8.8
CVE-2016-6893

Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the aut…

Mitigation only
Fix from $1,950 2016-09-02
Glibc MEDIUM 5.5
CVE-2015-8777

The process_envvars function in elf/rtld.c in the GNU C Library (aka glibc or libc6) before 2.23 allows local users to bypass a pointer-guarding prot…

Fix: after 2.22
Fix from $1,600 2016-01-20
Gcc MEDIUM 5.0
CVE-2015-5276

The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking so…

Fix: 4.9.4+
Fix from $1,600 2015-11-17
Gnu Screen MEDIUM 5.0
CVE-2015-6806

The MScrollV function in ansi.c in GNU screen 4.3.1 and earlier does not properly limit recursion, which allows remote attackers to cause a denial of…

Fix: after 4.3.1
Fix from $1,600 2015-09-28
Glibc MEDIUM 5.1
CVE-2013-7424

The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a d…

Fix: after 2.14.1
Fix from $1,600 2015-08-26
Gnutls MEDIUM 5.0
CVE-2015-0282

GnuTLS before 3.1.0 does not verify that the RSA PKCS #1 signature algorithm matches the signature algorithm in the certificate, which allows remote …

Fix: after 3.0.9
Fix from $1,600 2015-03-24
Glibc MEDIUM 5.0
CVE-2014-6040EPSS 7%

GNU C Library (aka glibc) before 2.20 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a multibyte …

Fix: after 2.19
Fix from $1,600 2014-12-05
Wget HIGH 9.3
CVE-2014-4877EPSS 40%

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and …

Fix: after 1.15
Fix from $1,950 2014-10-29
Glibc MEDIUM 6.8
CVE-2011-2702EPSS 8%

Integer signedness error in Glibc before 2.13 and eglibc before 2.13, when using Supplemental Streaming SIMD Extensions 3 (SSSE3) optimization, allow…

Fix: after 2.12.2
Fix from $1,600 2014-10-27
Glibc HIGH 7.5
CVE-2014-4043

The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which …

Fix: after 2.19
Fix from $1,950 2014-10-06
Bash HIGH 8.8
CVE-2014-6278 KEVEPSS 100%

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to…

Patch available
Fix from $1,950 2014-09-30