Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Grub2 MEDIUM 5.3
CVE-2024-56738

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

Fix: after 2.12
Fix from $1,600 2024-12-29
Emacs HIGH 7.8
CVE-2024-53920

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp sourc…

Fix: 30.1+
Fix from $1,950 2024-11-27
Emacs CRITICAL 9.8
CVE-2024-39331

In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-comm…

Fix: 29.4+
Fix from $2,300 2024-06-23
Wget CRITICAL 9.1
CVE-2024-38428

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data t…

Fix: after 1.24.5
Fix from $2,300 2024-06-16
Libcdio HIGH 8.4
CVE-2024-36600

Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.

Fix: 2.3.0+
Fix from $1,950 2024-06-14
Savane HIGH 7.6
CVE-2024-29399

An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted fil…

Fix: after 3.13
Fix from $1,950 2024-04-11
Savane HIGH 8.8
CVE-2024-27632

An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.

Fix: 3.13+
Fix from $1,950 2024-04-08
Savane MEDIUM 6.0
CVE-2024-27631

Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php

Fix: 3.13+
Fix from $1,600 2024-04-08
Savane HIGH 7.5
CVE-2024-27630

Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the t…

Fix: 3.13+
Fix from $1,950 2024-04-08
Grub2 MEDIUM 6.7
CVE-2024-2312

GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. Th…

Fix: 2.12-1ubuntu5+
Fix from $1,600 2024-04-05
Tar MEDIUM 6.2
CVE-2023-39804

In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.

Fix: 1.35+
Fix from $1,600 2024-03-27
Emacs HIGH 7.8
CVE-2024-30202

In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.

Fix: 9.6.23 / 29.3+
Fix from $1,950 2024-03-25
Indent MEDIUM 5.5
CVE-2024-0911

A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted fil…

Mitigation only
Fix from $1,600 2024-02-06
Coreutils MEDIUM 5.5
CVE-2024-0684

A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in t…

Patch available
Fix from $1,600 2024-02-06
Libredwg HIGH 7.5
CVE-2023-26157

Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pag…

Fix: 0.12.5.6384+
Fix from $1,950 2024-01-02
Grub MEDIUM 6.7
CVE-2023-4949

An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way…

Fix: after 0.97
Fix from $1,600 2023-11-10
Binutils HIGH 7.1
CVE-2023-25584

An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.

Fix: 2.40+
Fix from $1,950 2023-09-14
Binutils MEDIUM 5.5
CVE-2023-25585

A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of servic…

Patch available
Fix from $1,600 2023-09-14
Binutils MEDIUM 5.5
CVE-2023-25586

A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that c…

Patch available
Fix from $1,600 2023-09-14
Binutils MEDIUM 5.5
CVE-2023-25588

A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_symtab` function, which may le…

Patch available
Fix from $1,600 2023-09-14
Binutils HIGH 7.8
CVE-2022-44840

Heap buffer overflow vulnerability in binutils readelf before 2.40 via function find_section_in_set in file readelf.c.

Fix: 2.40+
Fix from $1,950 2023-08-22
Binutils HIGH 7.8
CVE-2022-45703

Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c.

Fix: 2.40+
Fix from $1,950 2023-08-22
Binutils HIGH 7.8
CVE-2022-47673

An issue was discovered in Binutils addr2line before 2.39.3, function parse_module contains multiple out of bound reads which may cause a denial of s…

Fix: 2.39.3+
Fix from $1,950 2023-08-22
Binutils HIGH 7.8
CVE-2022-47695

An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function bfd_ma…

Fix: 2.39.3+
Fix from $1,950 2023-08-22
Binutils HIGH 7.8
CVE-2022-47696

An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function compar…

Fix: 2.39.3+
Fix from $1,950 2023-08-22
Binutils MEDIUM 5.5
CVE-2022-47007

An issue was discovered function stab_demangle_v3_arg in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to mem…

Fix: after 2.38
Fix from $1,600 2023-08-22
Binutils MEDIUM 5.5
CVE-2022-47008

An issue was discovered function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of servic…

Fix: after 2.38
Fix from $1,600 2023-08-22
Binutils MEDIUM 5.5
CVE-2022-47010

An issue was discovered function pr_function_type in prdbg.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory …

Fix: after 2.38
Fix from $1,600 2023-08-22
Binutils MEDIUM 5.5
CVE-2022-47011

An issue was discovered function parse_stab_struct_fields in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to…

Fix: after 2.38
Fix from $1,600 2023-08-22
Binutils MEDIUM 5.5
CVE-2022-48063

GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function load_separate_debug_files at dwarf2…

Fix: 2.40+
Fix from $1,600 2023-08-22